In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24407.json",
"cna_assigner": "mitre"
}{
"extracted_events": [
{
"introduced": "2.1.17"
},
{
"fixed": "2.1.27"
},
{
"introduced": "0"
},
{
"fixed": "2.1.28"
}
],
"source": "DESCRIPTION"
}"2026-06-15T23:36:33Z"
[
{
"digest": {
"function_hash": "186791996052852124502521635320733420169",
"length": 1554.0
},
"signature_version": "v1",
"id": "CVE-2022-24407-5c873e4e",
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "plugins/ldapdb.c",
"function": "ldapdb_connect"
},
"source": "https://github.com/cyrusimap/cyrus-sasl/commit/0189425cc210555c36383293c468df5da73acc48"
},
{
"digest": {
"line_hashes": [
"144668858640807075656085101226286271128",
"211578268953532869409335602825794959431",
"96446337139993211718298955984275164381",
"167226722289251606297342675712617793056",
"206595935989217991224862346054111721781",
"50557079708634351328870234884447350999",
"184652442851362552426685588654803768615",
"43876264774750258202720770410034814538"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2022-24407-6810885d",
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "plugins/ldapdb.c"
},
"source": "https://github.com/cyrusimap/cyrus-sasl/commit/0189425cc210555c36383293c468df5da73acc48"
},
{
"digest": {
"function_hash": "330803884472733918276636343244308402752",
"length": 2959.0
},
"signature_version": "v1",
"id": "CVE-2022-24407-def92cbb",
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "plugins/ldapdb.c",
"function": "ldapdb_auxprop_lookup"
},
"source": "https://github.com/cyrusimap/cyrus-sasl/commit/0189425cc210555c36383293c468df5da73acc48"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-24407.json"