CVE-2023-31038

CWE-89SQL Injection6 documents6 sources
Severity
8.8HIGH
EPSS
0.4%
top 38.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 8
Latest updateJul 6

Description

SQL injection in Log4cxx when using the ODBC appender to send log messages to a database. No fields sent to the database were properly escaped for SQL injection. This has been the case since at least version 0.9.0(released 2003-08-06) Note that Log4cxx is a C++ framework, so only C++ applications are affected. Before version 1.1.0, the ODBC appender was automatically part of Log4cxx if the library was found when compiling the library. As of version 1.1.0, this must be both explicitly enabled

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDapache/log4cxx0.9.01.1.0
Debianlog4cxx< 1.1.0-1+1

🔴Vulnerability Details

3
GHSA
GHSA-76cx-3v2m-9952: SQL injection in Log4cxx when using the ODBC appender to send log messages to a database2023-07-06
OSV
CVE-2023-31038: SQL injection in Log4cxx when using the ODBC appender to send log messages to a database2023-05-08
CVEList
Apache Log4cxx: SQL injection when using ODBC appender2023-05-08

📋Vendor Advisories

2
Red Hat
log4cxx: SQL injection in Log4cxx when using the ODBC appender to send log messages to a database2023-05-07
Debian
CVE-2023-31038: log4cxx - SQL injection in Log4cxx when using the ODBC appender to send log messages to a ...2023
CVE-2023-31038 (HIGH CVSS 8.8) | SQL injection in Log4cxx when using | cvebase.io