Missing Authentication for Critical Function in Sphinx - CVE-2019-14511
Published: January 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to the database.
The vulnerability exists due to insecure default configuration in which Sphinx listens on 0.0.0.0 and does not require authentication to be configured. A remote non-authenticated attacker can simply connect to the database and gain full access to information.
Affected software
openEuler
Fedora
sphinx
libsphinxclient-devel
sphinx-php
libsphinxclient
sphinx-debuginfo
sphinx-java
sphinx-debugsource
sphinx-help
How to mitigate CVE-2019-14511
sphinx - update to 2.2.11-2
libsphinxclient-devel - update to 2.2.11-2
sphinx-php - update to 2.2.11-2
libsphinxclient - update to 2.2.11-2
sphinx-debuginfo - update to 2.2.11-2
sphinx-java - update to 2.2.11-2
sphinx-debugsource - update to 2.2.11-2
sphinx-help - update to 2.2.11-2
sphinx - addressed in versions 2.2.11-12.fc29, 2.2.11-12.fc30, 2.2.11-13.fc31
External References
- http://sphinxsearch.com/docs/sphinx3.html#getting-started-on-linux-and-macos
- https://blog.wirhabenstil.de/2019/08/19/sphinxsearch-0-0-0-09306-cve-2019-14511/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3FPPNZZMWTZOMFGFETMET6YKIH2DQDKS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XD25JJJVM7FFXAO2L3ZG2KXQ6UMFBIA4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YSLPW44RWIGHU5AG3P4U2HPSD3UBG4GJ/
- https://sphinxsearch.com/blog/