The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a local or restricted network were able to perform arbitrary SQL queries, discovering other users cached data. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: OX

Published: 2023-08-02T12:23:02.994Z

Updated: 2024-01-12T07:13:12.378Z

Reserved: 2023-02-22T20:42:56.090Z


Link: CVE-2023-26439

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-08-02T13:15:10.403

Modified: 2024-01-12T08:15:41.267


Link: CVE-2023-26439

JSON object: View

cve-icon Redhat Information

No data.

CWE