← Zuruck zu CVEs
CVE-2018-4056
CRITICAL9.8
Beschreibung
An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht2/5/2019
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
coturn_project:coturndebian:debian_linux
Schwachen (CWE)
CWE-89
Referenzen
https://lists.debian.org/debian-lts-announce/2019/02/msg00017.html(talos-cna@cisco.com)
https://talosintelligence.com/vulnerability_reports/TALOS-2018-0730(talos-cna@cisco.com)
https://www.debian.org/security/2019/dsa-4373(talos-cna@cisco.com)
https://lists.debian.org/debian-lts-announce/2019/02/msg00017.html(af854a3a-2127-422b-91ae-364da2661108)
https://talosintelligence.com/vulnerability_reports/TALOS-2018-0730(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2019/dsa-4373(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.