Security Advisory

CVE-2020-10184

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-03-05 22:48:35
Last updated 2024-08-04 10:58:39
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service; the issue does NOT affect YubiCloud.