Threat Advisory

Critical SQL Injection Flaws Expose Gentoo Soko to Remote Code Execution

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

 

Summary: [/subscribe_to_unlock_form]

 

Summary: [emaillocker id="1283"]

Gentoo Soko has multiple SQL injection vulnerabilities that can result in remote code execution (RCE) on vulnerable systems. Despite the utilization of an Object-Relational Mapping (ORM) library and prepared statements, SQL injections occurred in Gentoo Soko due to a database misconfiguration. This vulnerability has the potential to lead to remote code execution (RCE) on the Soko system. CVE-2023-28424 (CVSS score: 9.1) represents the collective tracking of two issues found in the search feature of Soko.

Soko, a Go software module, is responsible for powering packages.gentoo.org. It provides users with a convenient method to search through the various Portage packages available for the Gentoo Linux distribution. The identified shortcomings in the service made it possible for a malicious actor to potentially inject specially crafted code, leading to the exposure of sensitive information. The exploitable SQL injections had the capability to reveal the version of the PostgreSQL server and execute arbitrary commands on the system.

 

Recommendations:

We strongly recommend you download and apply the patch provided by Gentoo.

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/06/critical-sql-injection-flaws-expose.html

[/emaillocker]
crossmenu