cvelist/2022/2xxx/CVE-2022-2841.json

91 lines
3.3 KiB
JSON
Raw Normal View History

2022-08-16 12:00:39 +00:00
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2022-2841",
2022-08-22 10:02:01 +02:00
"TITLE": "CrowdStrike Falcon Uninstallation authorization",
"REQUESTER": "cna@vuldb.com",
"ASSIGNER": "cna@vuldb.com",
"STATE": "PUBLIC"
},
"generator": "vuldb.com",
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "CrowdStrike",
"product": {
"product_data": [
{
"product_name": "Falcon",
"version": {
"version_data": [
{
"version_value": "6.31.14505.0"
},
{
"version_value": "6.42.15610"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-862 Missing Authorization"
}
]
}
]
2022-08-16 12:00:39 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2022-08-22 09:00:45 +00:00
"value": "A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610. It has been classified as problematic. Affected is the Uninstallation Handler which makes it possible to circumvent and disable the security feature. The manipulation leads to missing authorization. The identifier of this vulnerability is VDB-206880."
2022-08-22 10:02:01 +02:00
}
]
},
2022-08-22 09:00:45 +00:00
"credit": "Pascal Zenker/Max Moser",
2022-08-22 10:02:01 +02:00
"impact": {
"cvss": {
"version": "3.1",
"baseScore": "2.7",
2022-08-22 09:00:45 +00:00
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L"
2022-08-22 10:02:01 +02:00
}
},
"references": {
"reference_data": [
{
2022-08-22 09:00:45 +00:00
"url": "https://www.modzero.com/modlog/archives/2022/08/22/ridiculous_vulnerability_disclosure_process_with_crowdstrike_falcon_sensor/index.html",
"refsource": "MISC",
"name": "https://www.modzero.com/modlog/archives/2022/08/22/ridiculous_vulnerability_disclosure_process_with_crowdstrike_falcon_sensor/index.html"
2022-08-22 10:02:01 +02:00
},
{
2022-08-22 09:00:45 +00:00
"url": "https://www.modzero.com/advisories/MZ-22-02-CrowdStrike-FalconSensor.txt",
"refsource": "MISC",
"name": "https://www.modzero.com/advisories/MZ-22-02-CrowdStrike-FalconSensor.txt"
2022-08-22 10:02:01 +02:00
},
{
2022-08-22 09:00:45 +00:00
"url": "https://youtu.be/3If-Fqwx-4s",
"refsource": "MISC",
"name": "https://youtu.be/3If-Fqwx-4s"
2022-08-22 10:02:01 +02:00
},
{
2022-08-22 09:00:45 +00:00
"url": "https://vuldb.com/?id.206880",
"refsource": "MISC",
"name": "https://vuldb.com/?id.206880"
2022-08-16 12:00:39 +00:00
}
]
}
}