Improper Input Validation Affecting asterisk package, versions [16.0.0, 16.25.2)[18.0.0,18.11.2)[19.0.0,19.3.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
6.98% (94th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-ASTERISK-2764996
  • published15 Apr 2022
  • disclosed15 Apr 2022
  • creditUnknown

Introduced: 15 Apr 2022

CVE-2022-26651  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade asterisk to version 16.25.2, 18.11.2, 19.3.2 or higher.

Overview

Affected versions of this package are vulnerable to Improper Input Validation. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly a SQL injection. This is fixed in 16.25.2, 18.11.2, and 19.3.2, and 16.8-cert14.

References

CVSS Base Scores

version 3.1