syslog-ng
cpe:2.3:a:oneidentity:syslog-ng:*:*:*:*:*:*:*
- < 4.12
A SQL injection vulnerability has been identified in syslog-ng versions prior to 4.12, as well as in syslog-ng Premium Edition versions prior to 8.2 and syslog-ng Store Box versions prior to 7.8. The issue arises from a missing sanitization call in the AFSQl destination driver, allowing untrusted sources to inject malicious SQL. This vulnerability is not part of the default configuration and requires the SQL driver to be manually enabled.
Exploitation of this vulnerability could lead to SQL injection, allowing attackers to manipulate SQL queries and potentially access or modify database information.
Users can update to syslog-ng 4.12, syslog-ng Premium Edition 8.2, or syslog-ng Store Box 7.8 to address this vulnerability. If the SQL driver is used, implement server-side query sanitization as an additional precaution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.