GHSA-27qr-636m-wxg2

Suggest an improvement
Source
https://github.com/advisories/GHSA-27qr-636m-wxg2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-27qr-636m-wxg2/GHSA-27qr-636m-wxg2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-27qr-636m-wxg2
Published
2024-05-15T18:09:41Z
Modified
2024-11-29T05:35:58Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L CVSS Calculator
Summary
codeigniter/framework SQL injection in ODBC database driver
Details

CodeIgniter 3.1.0 addressed a critical security issue within the ODBC database driver. This update includes crucial fixes to mitigate a SQL injection vulnerability, preventing potential exploitation by attackers. It is noteworthy that these fixes render the query builder and escape() functions incompatible with the ODBC driver. However, the update introduces actual query binding as a more secure alternative.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-05-15T18:09:41Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

Packagist / codeigniter/framework

Package

Name
codeigniter/framework
Purl
pkg:composer/codeigniter/framework

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.0

Affected versions

3.*
3.0rc
3.0rc2
3.0rc3
3.0.0
3.0.1rc
3.0.1rc2
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-27qr-636m-wxg2/GHSA-27qr-636m-wxg2.json"