Vital SQL Injection Vulnerability in Apache Site visitors Management Rated 9.9 CVSS — Patch Now

Dec 25, 2024Ravie LakshmananServer Safety / Vulnerability

The Apache Software program Basis (ASF) has shipped safety updates to deal with a essential safety flaw in Site visitors Management that, if efficiently exploited, might enable an attacker to execute arbitrary Structured Question Language (SQL) instructions within the database.

The SQL injection vulnerability, tracked as CVE-2024-45387, is rated 9.9 out of 10.0 on the CVSS scoring system.

“An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role ‘admin,’ ‘federation,’ ‘operations,’ ‘portal,’ or ‘steering’ to execute arbitrary SQL against the database by sending a specially-crafted PUT request,” venture maintainers stated in an advisory.

Apache Site visitors Management is an open-source implementation of a Content material Supply Community (CDN). It was introduced as a top-level venture (TLP) by the AS in June 2018.

Cybersecurity

Tencent YunDing Safety Lab researcher Yuan Luo has been credited with discovering and reporting the vulnerability. It has been patched in model Apache Site visitors Management 8.0.2.

The event comes because the ASF has resolved an authentication bypass flaw in Apache HugeGraph-Server (CVE-2024-43441) from variations 1.0 via 1.3. A repair for the shortcoming has been launched in model 1.5.0.

It additionally follows the discharge of a patch for an vital vulnerability in Apache Tomcat (CVE-2024-56337) that might end in distant code execution (RCE) below sure situations.

Customers are really helpful to replace their cases to the newest variations of the software program to guard in opposition to potential threats.

Discovered this text attention-grabbing? Comply with us on Twitter and LinkedIn to learn extra unique content material we publish.

Recent articles

Ruijie Networks’ Cloud Platform Flaws Might Expose 50,000 Units to Distant Assaults

Dec 25, 2024Ravie LakshmananCloud Security / Vulnerability Cybersecurity researchers have...

Iran’s Charming Kitten Deploys BellaCPP: A New C++ Variant of BellaCiao Malware

Dec 25, 2024Ravie LakshmananCyber Assault / Malware The Iranian nation-state...

Postman Workspaces Leak 30000 API Keys and Delicate Tokens

SUMMARY 30,000 Public Workspaces Uncovered: CloudSEK identifies large information leaks...