CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
53.2%
Users of a12nserver that use MySQL might be vulnerable to SQL injection bugs.
If you use a12nserver and MySQL, update as soon as possible. This SQL injection bug might let an attacker obtain OAuth2 Access Tokens for users unrelated to those that permitted OAuth2 clients.
The knex dependency has been updated to 2.4.0 in a12nserver 0.23.0
No further workarounds
Vendor | Product | Version | CPE |
---|---|---|---|
curveball | a12n-server | * | cpe:2.3:a:curveball:a12n-server:*:*:*:*:*:*:*:* |
github.com/advisories/GHSA-crhg-xgrg-vvcc
github.com/curveball/a12n-server/commit/f4acd7549043e6e2b8917b77a50dce0756a922cc
github.com/curveball/a12n-server/releases/tag/v0.23.0
github.com/curveball/a12n-server/security/advisories/GHSA-crhg-xgrg-vvcc
github.com/knex/knex/issues/1227
nvd.nist.gov/vuln/detail/CVE-2016-20018
www.ghostccamm.com/blog/knex_sqli/