Missing Authentication for Critical Function in Sphinx - CVE-2019-14511

 

Missing Authentication for Critical Function in Sphinx - CVE-2019-14511

Published: January 11, 2022


Vulnerability identifier: #VU59363
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14511
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to the database.

The vulnerability exists due to insecure default configuration in which Sphinx listens on 0.0.0.0 and does not require authentication to be configured. A remote non-authenticated attacker can simply connect to the database and gain full access to information.


Affected software

Sphinx
openEuler
Fedora
sphinx
libsphinxclient-devel
sphinx-php
libsphinxclient
sphinx-debuginfo
sphinx-java
sphinx-debugsource
sphinx-help

How to mitigate CVE-2019-14511

Install updates from vendor's website.

Sphinx - update to 3.2.1
sphinx - update to 2.2.11-2
libsphinxclient-devel - update to 2.2.11-2
sphinx-php - update to 2.2.11-2
libsphinxclient - update to 2.2.11-2
sphinx-debuginfo - update to 2.2.11-2
sphinx-java - update to 2.2.11-2
sphinx-debugsource - update to 2.2.11-2
sphinx-help - update to 2.2.11-2
sphinx - addressed in versions 2.2.11-12.fc29, 2.2.11-12.fc30, 2.2.11-13.fc31

External References

Related Security Bulletins