mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-08-04 08:44:25 +00:00
91 lines
3.3 KiB
JSON
91 lines
3.3 KiB
JSON
{
|
|
"data_type": "CVE",
|
|
"data_format": "MITRE",
|
|
"data_version": "4.0",
|
|
"CVE_data_meta": {
|
|
"ID": "CVE-2022-2841",
|
|
"TITLE": "CrowdStrike Falcon Uninstallation authorization",
|
|
"REQUESTER": "cna@vuldb.com",
|
|
"ASSIGNER": "cna@vuldb.com",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"generator": "vuldb.com",
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "CrowdStrike",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "Falcon",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "6.31.14505.0"
|
|
},
|
|
{
|
|
"version_value": "6.42.15610"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "CWE-862 Missing Authorization"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610. It has been classified as problematic. Affected is the Uninstallation Handler which makes it possible to circumvent and disable the security feature. The manipulation leads to missing authorization. The identifier of this vulnerability is VDB-206880."
|
|
}
|
|
]
|
|
},
|
|
"credit": "Pascal Zenker/Max Moser",
|
|
"impact": {
|
|
"cvss": {
|
|
"version": "3.1",
|
|
"baseScore": "2.7",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L"
|
|
}
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"url": "https://www.modzero.com/modlog/archives/2022/08/22/ridiculous_vulnerability_disclosure_process_with_crowdstrike_falcon_sensor/index.html",
|
|
"refsource": "MISC",
|
|
"name": "https://www.modzero.com/modlog/archives/2022/08/22/ridiculous_vulnerability_disclosure_process_with_crowdstrike_falcon_sensor/index.html"
|
|
},
|
|
{
|
|
"url": "https://www.modzero.com/advisories/MZ-22-02-CrowdStrike-FalconSensor.txt",
|
|
"refsource": "MISC",
|
|
"name": "https://www.modzero.com/advisories/MZ-22-02-CrowdStrike-FalconSensor.txt"
|
|
},
|
|
{
|
|
"url": "https://youtu.be/3If-Fqwx-4s",
|
|
"refsource": "MISC",
|
|
"name": "https://youtu.be/3If-Fqwx-4s"
|
|
},
|
|
{
|
|
"url": "https://vuldb.com/?id.206880",
|
|
"refsource": "MISC",
|
|
"name": "https://vuldb.com/?id.206880"
|
|
}
|
|
]
|
|
}
|
|
} |