Scheduled maintenance: Some features related to account registration and licensing may be temporarily unavailable from Friday (May 8) at 1 PM to Sunday (May 10) at 5 PM (PST).
HomeDefectsLIN1023-21522
Acknowledged

LIN1023-21522 : Security Advisory - cyrus-sasl - CVE-2022-24407

Created: Apr 27, 2026    Updated: Apr 30, 2026
Found In Version: 10.23.30.22
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

https://nvd.nist.gov/vuln/detail/CVE-2022-24407