Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc5bWctNHcyMy00ZnFj
Unauthenticated SQL Injection in Cachet
Impact
In Cachet versions through 2.3.18, there is a SQL injection which is in the SearchableTrait#scopeSearch()
. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session.
Patches
The original repository of https://github.com/CachetHQ/Cachet is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected.
Update to version 2.5 or later in the https://github.com/fiveai/Cachet fork to fix this vulnerability.
Permalink: https://github.com/advisories/GHSA-79mg-4w23-4fqcJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc5bWctNHcyMy00ZnFj
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 3 years ago
Updated: almost 2 years ago
CVSS Score: 8.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Identifiers: GHSA-79mg-4w23-4fqc, CVE-2021-39165
References:
- https://github.com/fiveai/Cachet/security/advisories/GHSA-79mg-4w23-4fqc
- https://github.com/fiveai/Cachet/commit/27bca8280419966ba80c6fa283d985ddffa84bb6
- https://nvd.nist.gov/vuln/detail/CVE-2021-39165
- https://github.com/advisories/GHSA-79mg-4w23-4fqc
Blast Radius: 6.8
Affected Packages
packagist:cachethq/cachet
Dependent packages: 2Dependent repositories: 7
Downloads: 393 total
Affected Version Ranges: <= 2.3.18
No known fixed version
All affected versions: 1.0.0, 1.1.0, 1.1.1, 1.2.0, 1.2.1, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.2.0, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.3.7, 2.3.8, 2.3.9, 2.3.10, 2.3.11, 2.3.12, 2.3.13, 2.3.14, 2.3.15, 2.3.16, 2.3.17, 2.3.18