Oval Definition:oval:com.ubuntu.bionic:def:2020101840000000
Revision Date:2020-03-05Version:1
Title:CVE-2020-10184 on Ubuntu 18.04 LTS (bionic) - medium.
Description:The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service; the issue does NOT affect YubiCloud.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2020-10184
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND yubikey-val package in bionic is affected and may need fixing.
  • BACK