PublicDateAtUSN: 2022-02-22 18:00:00 UTC Candidate: CVE-2022-24407 CRD: 2022-02-22 18:00:00 UTC PublicDate: 2022-02-24 15:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24407 https://ubuntu.com/security/notices/USN-5301-1 https://ubuntu.com/security/notices/USN-5301-2 Description: In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: high Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_cyrus-sasl2: upstream: https://github.com/cyrusimap/cyrus-sasl/commit/2d2e97b0eb53fa7f87a3bf1529d8f712dd954480 upstream_cyrus-sasl2: released (2.1.28) trusty/esm_cyrus-sasl2: released (2.1.25.dfsg1-17ubuntu0.1~esm2) esm-infra/xenial_cyrus-sasl2: released (2.1.26.dfsg1-14ubuntu0.2+esm1) bionic_cyrus-sasl2: released (2.1.27~101-g0780600+dfsg-3ubuntu2.4) focal_cyrus-sasl2: released (2.1.27+dfsg-2ubuntu0.1) impish_cyrus-sasl2: released (2.1.27+dfsg-2.1ubuntu0.1) jammy_cyrus-sasl2: released (2.1.27+dfsg2-3ubuntu1) devel_cyrus-sasl2: released (2.1.27+dfsg2-3ubuntu1)