SQL injection in Apache Traffic Control in github.com/apache/trafficcontrol
SQL injection in Apache Traffic Control in github.com/apache/trafficcontrol
02 / AFFECTED SOFTWARE
Affected packages
10 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.
SQL injection in Apache Traffic Control in github.com/apache/trafficcontrol
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2024/12/23/3
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45387.json
- https://lists.apache.org/thread/t38nk5n7t8w3pb66z7z4pqfzt4443trr
- https://nvd.nist.gov/vuln/detail/CVE-2024-45387
- https://github.com/advisories/GHSA-vq94-9pfv-ccqr
- https://github.com/apache/trafficcontrol/releases/tag/v8.0.2
- https://github.com/apache/trafficcontrol