PT-2022-24443 · Archery · Archery

Bit-Sec

·

Published

2022-09-13

·

Updated

2022-11-08

·

CVE-2022-38537

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Archery versions 1.4.5 through 1.8.5
Description The issue concerns multiple SQL injection vulnerabilities. These vulnerabilities exist via the start file, end file, start time, and stop time parameters in the binlog2sql interface.
Recommendations For versions 1.4.5 through 1.8.5, consider restricting access to the binlog2sql interface until a patch is available. As a temporary workaround, avoid using the start file, end file, start time, and stop time parameters in the binlog2sql interface to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-38537

Affected Products

Archery