Yubiserver SQL Injection Vulnerability Allowing Authentication Bypass

Vulnerability

A SQL injection vulnerability has been identified in Yubiserver versions prior to 0.6. This issue could potentially lead to an authentication bypass. The vulnerability arises from improper handling of SQL queries, which could allow an attacker to manipulate query parameters and bypass authentication mechanisms.

Impact

Exploitation of this vulnerability could allow unauthorized users to gain access by bypassing authentication requirements.

Remediation

Users can upgrade to Yubiserver version 0.6-1 or later to address this vulnerability. Instructions for upgrading are available through the Debian Package Management System.

Added: Jun 26, 2025, 10:55 PM
Updated: Jun 26, 2025, 10:55 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.