OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to execute arbitrary SQL statements. Exploitation requires no authentication or user interaction and can result in complete compromise of the underlying database. All deployments of Open XDMoD prior to 10.0.3 are impacted. This issue was discovered on 2023-08-03 and patched on 2023-08-04. At this time there is no evidence that this vulnerability has been exploited in the wild. The vulnerability was patched in Open XDMoD 10.0.3 on 2023-08-04. As a workaround, apply the patch manually.
The vulnerability (CWE-89) consists of a lack of proper validation or parameterization of input data passed to SQL queries. An attacker can craft a malicious network request containing additional SQL instructions that will be executed by the database engine. Exploitation is possible remotely, without possessing any account in the system, which drastically lowers the barrier to entry for potential attackers.
Successful exploitation of the vulnerability can lead to complete takeover of the database — reading, modifying, or deleting data, and potentially lateral movement within the infrastructure. The consequence may be a complete breach of confidentiality, integrity, and availability of stored HPC data.
Open XDMoD should be updated to version 10.0.3 or later (patch released 2023-08-04). For environments where immediate updating is not possible, the vendor provides manual patches: for versions 0.0.0–8.6.0 at https://open.xdmod.org/security_patches/GHSA-r33r-6g3c-r992-0_0_0-8_6_0.patch and for versions 9.0.0–10.0.2 at https://open.xdmod.org/security_patches/GHSA-r33r-6g3c-r992-9_0_0-10_0_2.patch.
All deployments of Open XDMoD in versions prior to 10.0.3, including versions from the 0.0.0–8.6.0 and 9.0.0–10.0.2 branches.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XBuffalo Open Xdmod
APPBuffalo< 10.0.3
Related vulnerabilities
RCE poprzez command injection w Open XDMoD (wersje 9.5.0–11.0.2)
Open XDMoD – obejście uwierzytelnienia przez słaby mechanizm resetowania hasła
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authentic...
An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal...
OpenXDMoD to otwarty framework do zbierania i analizowania metryk HPC. Przed wersją 11.0.3 usterka w logice ko...