yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.
References
| Link | Resource |
|---|---|
| http://www.include.gr/debian/yubiserver/#changelog | Release Notes |
| https://bugs.debian.org/796495 | Issue Tracking Mailing List Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-06-26 22:15
Updated : 2025-08-06 15:38
NVD link : CVE-2015-0842
Mitre link : CVE-2015-0842
CVE.ORG link : CVE-2015-0842
JSON object : View
Products Affected
debian
- yubiserver
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
