CVE-2022-24831
Last modified
CVE-2022-24831 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). Versions prior to 3.16.1 are vulnerable to SQL injection due to the use of string concatenation to create SQL queries instead of prepared statements. EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). Versions prior to 3.16.1 are vulnerable to SQL injection due to the use of string concatenation to create SQL queries instead of prepared statements. No known workarounds exist. This issue has been patched in 3.16.1, 3.15.9, 3.14.1, and 3.13.1 and users are advised to upgrade.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openclinica | Openclinica | < 3.13.1 |
| Openclinica | Openclinica | > 3.15, < 3.15.9 |
| Openclinica | Openclinica | > 3.16, < 3.16.1 |
| Openclinica | Openclinica | 3.14 |
References
- https://github.com/OpenClinica/OpenClinica/pull/3490/commits/b152cc63019230c9973965a98e4386ea5322c18fPatch, Third Party Advisory
- https://github.com/OpenClinica/OpenClinica/security/advisories/GHSA-5289-4jwp-xp9hPatch, Third Party Advisory
- https://github.com/OpenClinica/OpenClinica/pull/3490/commits/b152cc63019230c9973965a98e4386ea5322c18fPatch, Third Party Advisory
- https://github.com/OpenClinica/OpenClinica/security/advisories/GHSA-5289-4jwp-xp9hPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-24831?
How severe is CVE-2022-24831?
How do I fix CVE-2022-24831?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-24826On Windows, if Git LFS operates on a malicious repository wi…7.8
- CVE-2022-24827Elide is a Java library that lets you stand up a GraphQL/JSO…8.1
- CVE-2022-24828Composer is a dependency manager for the PHP programming lan…8.8
- CVE-2022-24829Garden is an automation platform for Kubernetes development …9.8
- CVE-2022-2483 The bootloader in the Nokia ASIK AirScale system module (ve…7.1
- CVE-2022-24830OpenClinica is an open source software for Electronic Data C…9.8
- CVE-2022-24832GoCD is an open source a continuous delivery server. The bun…6.8
- CVE-2022-24833PrivateBin is minimalist, open source online pastebin clone …6.1
- CVE-2022-24834Redis is an in-memory database that persists on disk. A spec…8.8
- CVE-2022-24836Nokogiri is an open source XML and HTML library for Ruby. No…7.5
- CVE-2022-24837HedgeDoc is an open-source, web-based, self-hosted, collabor…5.3
- CVE-2022-24838Nextcloud Calendar is a calendar application for the nextclo…9.8
Are you affected by CVE-2022-24831?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
