Junglewise Threat Intelligence

CVE-2020-36645: Square Squalor SQL injection

CVE-2020-36645 · Severity: critical · CVSS 9.8 · Published 2023-01-07

Vendors: Go.

Executive brief

Square Squalor is a library used by developers to interact with SQL databases in Go-based applications. A critical vulnerability allows attackers to perform SQL injection, which could lead to unauthorized access, modification, or deletion of sensitive data stored in the database. Organizations using this library should update to the patched version immediately to prevent potential data breaches.

Technical details

A SQL injection vulnerability (CWE-89) exists in Square Squalor, a Go library for SQL database interaction. The flaw stems from the improper neutralization of user-influenced input when constructing SQL commands. A remote, unauthenticated attacker can exploit this by providing specially crafted input that modifies the intended SQL query structure. Successful exploitation allows for full read, write, and delete access to the underlying database. The issue is addressed in version 0.0.0-20200306154055-f6f0a47cc344 (commit f6f0a47).

Affected products

  • Square squalor < 0.0.0-20200306154055-f6f0a47cc344

Timeline

  • 2023-01-07: advisory
  • 2020-03-06: patched: Date based on version string timestamp

References