Ir para o conteúdo
Informational

High

Resolved Post-auth SQLi in Capsule8 Console (CVE-2022-0366)

CVE(N)

CVE-2022-0366

PRODUTO(S)

Capsule8 Console

Atualizado

2022 Feb 1

Versão do artigo

1

Publicado

2022 Feb 1

ID de publicação

sophos-sa-20220201-cap8-console-sqli

Solução alternativa

No

Overview

A post-auth SQL injection vulnerability in the Capsule8 Console was discovered by Sophos during internal security testing. The vulnerability has been fixed.

The remediation prevented a previously authorized agent from gaining administrative access on Console.

Applies to the following Sophos product(s) and version(s)

  • Capsule8 Console versions 4.6.0 through 4.9.1 inclusive

Remediation

  • Fix included in Capsule8 Console 4.10.0 on February 1, 2022

  • Users of older versions of Capsule8 Console are required to upgrade to receive this fix

  • Sophos always recommends that Capsule8 customers upgrade to the latest available release at their earliest opportunity

Sophos Logo

Sophos Responsible Disclosure Policy

To learn about Sophos security vulnerability disclosure policies and publications, see the Responsible Disclosure Policy.