A vulnerability, which was classified as critical, was found in Blue Yonder postgraas_server up to 2.0.0b2. Affected is the function _create_pg_connection/create_postgres_db of the file postgraas_server/backends/postgres_cluster/postgres_cluster_driver.py of the component PostgreSQL Backend Handler. The manipulation leads to sql injection. Upgrading to version 2.0.0 is able to address this issue. The patch is identified as 7cd8d016edc74a78af0d81c948bfafbcc93c937c. It is recommended to upgrade the affected component. VDB-234246 is the identifier assigned to this vulnerability.
References
Link | Resource |
---|---|
https://github.com/blue-yonder/postgraas_server/commit/7cd8d016edc74a78af0d81c948bfafbcc93c937c | Patch |
https://github.com/blue-yonder/postgraas_server/releases/tag/v2.0.0 | Release Notes |
https://vuldb.com/?ctiid.234246 | Permissions Required |
https://vuldb.com/?id.234246 | Third Party Advisory |
https://github.com/blue-yonder/postgraas_server/commit/7cd8d016edc74a78af0d81c948bfafbcc93c937c | Patch |
https://github.com/blue-yonder/postgraas_server/releases/tag/v2.0.0 | Release Notes |
https://vuldb.com/?ctiid.234246 | Permissions Required |
https://vuldb.com/?id.234246 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:03
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/blue-yonder/postgraas_server/commit/7cd8d016edc74a78af0d81c948bfafbcc93c937c - Patch | |
References | () https://github.com/blue-yonder/postgraas_server/releases/tag/v2.0.0 - Release Notes | |
References | () https://vuldb.com/?ctiid.234246 - Permissions Required | |
References | () https://vuldb.com/?id.234246 - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 5.2
v3 : 5.5 |
28 Jul 2023, 13:18
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:blueyonder:postgraas_server:2.0.0:beta2:*:*:*:*:*:* cpe:2.3:a:blueyonder:postgraas_server:*:*:*:*:*:*:*:* cpe:2.3:a:blueyonder:postgraas_server:2.0.0:beta1:*:*:*:*:*:* |
|
References | (MISC) https://vuldb.com/?id.234246 - Third Party Advisory | |
References | (MISC) https://github.com/blue-yonder/postgraas_server/commit/7cd8d016edc74a78af0d81c948bfafbcc93c937c - Patch | |
References | (MISC) https://vuldb.com/?ctiid.234246 - Permissions Required | |
References | (MISC) https://github.com/blue-yonder/postgraas_server/releases/tag/v2.0.0 - Release Notes | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
18 Jul 2023, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-18 13:15
Updated : 2024-11-21 04:03
NVD link : CVE-2018-25088
Mitre link : CVE-2018-25088
CVE.ORG link : CVE-2018-25088
JSON object : View
Products Affected
blueyonder
- postgraas_server
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')