CVE-2019-10141
published 2019-07-30CVE-2019-10141: A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in…
PriorityP355critical9.1CVSS 3.0
AVNACLPRNUINSUCNIHAH
EPSS
2.46%
82.6th percentile
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ironic-inspector | < ironic-inspector 8.0.0-3 (bookworm) | ironic-inspector 8.0.0-3 (bookworm) |
| openstack | ironic-inspector | < 5.0.2 | 5.0.2 |
| openstack | ironic-inspector | >= 0 < 8.0.0-3 | 8.0.0-3 |
| openstack | ironic-inspector | >= 0 < 8.0.0-3 | 8.0.0-3 |
| openstack | ironic-inspector | >= 0 < 8.0.0-3 | 8.0.0-3 |
| openstack | ironic-inspector | >= 0 < 8.0.0-3 | 8.0.0-3 |
| openstack | ironic-inspector | >= 0 < 5.0.2 | 5.0.2 |
| openstack | ironic-inspector | >= 5.1.0 < 6.0.3 | 6.0.3 |
| openstack | ironic-inspector | >= 5.1.0 < 6.0.3 | 6.0.3 |
| openstack | ironic-inspector | >= 6.1.0 < 7.2.4 | 7.2.4 |
| openstack | ironic-inspector | >= 6.1.0 < 7.2.4 | 7.2.4 |
| openstack | ironic-inspector | >= 8.0.0 < 8.0.3 | 8.0.3 |
| openstack | ironic-inspector | >= 8.0.0 < 8.0.3 | 8.0.3 |
| openstack | ironic-inspector | >= 8.1.0 < 8.2.1 | 8.2.1 |
| openstack | ironic-inspector | >= 8.1.0 < 8.2.1 | 8.2.1 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack-ironic-inspector | — | — |
| redhat | openstack-ironic-inspector | — | — |
| redhat | openstack-ironic-inspector | — | — |
| redhat | openstack-ironic-inspector | — | — |
| redhat | openstack-ironic-inspector | — | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv9.1CRITICAL
vendor_debian8.3HIGH
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Openstack ironic-inspector has SQL injection vulnerability in node_cache
ghsa·2022-05-24
CVE-2019-10141 [HIGH] CWE-89 Openstack ironic-inspector has SQL injection vulnerability in node_cache
Openstack ironic-inspector has SQL injection vulnerability in node_cache
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service.
OSV
Openstack ironic-inspector has SQL injection vulnerability in node_cache
osv·2022-05-24
CVE-2019-10141 [HIGH] Openstack ironic-inspector has SQL injection vulnerability in node_cache
Openstack ironic-inspector has SQL injection vulnerability in node_cache
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service.
OSV
MariaDB vulnerabilities
osv·2019-08-12·CVSS 4.9
CVE-2019-2737 MariaDB vulnerabilities
MariaDB vulnerabilities
USN-4070-1 fixed multiple vulnerabilities in MySQL. This update provides the
corresponding fixes for CVE-2019-2737, CVE-2019-2739, CVE-2019-2740,
CVE-2019-2805 in MariaDB 10.1.
Ubuntu 18.04 LTS has been updated to MariaDB 10.1.41.
In addition to security fixes, the updated package contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
https://mariadb.com/kb/en/library/mariadb-10141-changelog/
https://mariadb.com/kb/en/library/mariadb-10141-release-notes/
Original advisory details:
Multiple security issues were discovered in MySQL and this update includes
a new upstream MySQL version to fix these issues.
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.04 have been updated to
MySQL 5.7.27.
In additi
OSV
CVE-2019-10141: A vulnerability was found in openstack-ironic-inspector all versions excluding 5
osv·2019-07-30·CVSS 9.1
CVE-2019-10141 [CRITICAL] CVE-2019-10141: A vulnerability was found in openstack-ironic-inspector all versions excluding 5
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service.
Red Hat
openstack-ironic-inspector: SQL Injection vulnerability when receiving introspection data
vendor_redhat·2019-05-15·CVSS 8.3
CVE-2019-10141 [HIGH] CWE-89 openstack-ironic-inspector: SQL Injection vulnerability when receiving introspection data
openstack-ironic-inspector: SQL Injection vulnerability when receiving introspection data
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service.
A SQL-injection vulnerability
Debian
CVE-2019-10141: ironic-inspector - A vulnerability was found in openstack-ironic-inspector all versions excluding 5...
vendor_debian·2019·CVSS 8.3
CVE-2019-10141 [HIGH] CVE-2019-10141: ironic-inspector - A vulnerability was found in openstack-ironic-inspector all versions excluding 5...
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service.
Scope: local
bookworm: resolved (fixed in 8.0.0-3)
bullseye: resolved (fixed in 8.0.0-3)
forky: resolved (fixed in 8.0.0-3
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10141 openstack-ironic-inspector: SQL Injection vulnerability when receiving introspection data [openstack-rdo]
bugzilla·2019-05-21·CVSS 8.3
CVE-2019-10141 [HIGH] CVE-2019-10141 openstack-ironic-inspector: SQL Injection vulnerability when receiving introspection data [openstack-rdo]
CVE-2019-10141 openstack-ironic-inspector: SQL Injection vulnerability when receiving introspection data [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discu
Bugzilla
CVE-2019-10141 openstack-ironic-inspector: SQL Injection vulnerability when receiving introspection data
bugzilla·2019-05-19·CVSS 8.3
CVE-2019-10141 [HIGH] CVE-2019-10141 openstack-ironic-inspector: SQL Injection vulnerability when receiving introspection data
CVE-2019-10141 openstack-ironic-inspector: SQL Injection vulnerability when receiving introspection data
There is an SQL-injection vulnerability in the inpector's node_cache.find_node(). This function makes an SQL query using unescaped data received on the wire from a server reporting inspection results (specifically, via a POST to the /v1/continue endpoint).
The unescaped data should not be trusted - the API is unauthenticated and it's likely that anything with access to the network on which ironic-inspector is listening could exploit the vulnerability.
Because of how the results of the query are used, there appears to be no way to exploit this vulnerability to exfiltrate data. It could be exploited for destructive ends by passing malicious data (e.g. "\'; DROP DATABASE;\'").
Every re
https://access.redhat.com/errata/RHSA-2019:2505https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10141https://docs.openstack.org/releasenotes/ironic-inspector/ocata.html#relnotes-5-0-2-7-origin-stable-ocatahttps://docs.openstack.org/releasenotes/ironic-inspector/pike.html#relnotes-6-0-3-4-stable-pikehttps://docs.openstack.org/releasenotes/ironic-inspector/queens.html#relnotes-7-2-4-stable-queenshttps://docs.openstack.org/releasenotes/ironic-inspector/rocky.html#relnotes-8-0-3-stable-rockyhttps://docs.openstack.org/releasenotes/ironic-inspector/stein.html#relnotes-8-2-1-stable-steinhttps://access.redhat.com/errata/RHSA-2019:2505https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10141https://docs.openstack.org/releasenotes/ironic-inspector/ocata.html#relnotes-5-0-2-7-origin-stable-ocatahttps://docs.openstack.org/releasenotes/ironic-inspector/pike.html#relnotes-6-0-3-4-stable-pikehttps://docs.openstack.org/releasenotes/ironic-inspector/queens.html#relnotes-7-2-4-stable-queenshttps://docs.openstack.org/releasenotes/ironic-inspector/rocky.html#relnotes-8-0-3-stable-rockyhttps://docs.openstack.org/releasenotes/ironic-inspector/stein.html#relnotes-8-2-1-stable-stein
2019-07-30
Published