A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2018-12-13T22:00:00

Updated: 2024-08-05T09:29:51.865Z

Reserved: 2018-07-27T00:00:00

Link: CVE-2018-14623

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-12-14T00:29:01.127

Modified: 2023-02-12T23:31:56.983

Link: CVE-2018-14623

cve-icon Redhat

Severity : Low

Publid Date: 2018-12-12T00:00:00Z

Links: CVE-2018-14623 - Bugzilla