René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

113 lines
3.3 KiB
JSON

{
"id": "CVE-2022-30239",
"sourceIdentifier": "cve@mitre.org",
"published": "2022-05-09T18:15:08.783",
"lastModified": "2022-05-18T14:18:29.817",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena JDBC Driver 2.0.25 through 2.0.28 may allow a local user to execute code. NOTE: this is different from CVE-2022-29971."
},
{
"lang": "es",
"value": "Una vulnerabilidad de inyecci\u00f3n de argumentos en el componente de autenticaci\u00f3n basado en el navegador del controlador JDBC de Magnitude Simba Amazon Athena versiones 2.0.25 hasta 2.0.28 puede permitir que un usuario local ejecute c\u00f3digo. NOTA: esto es diferente de CVE-2022-29971"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 7.2
},
"baseSeverity": "HIGH",
"exploitabilityScore": 3.9,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-88"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:insightsoftware:magnitude_simba_amazon_athena_jdbc_driver:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.0.25",
"versionEndExcluding": "2.0.29",
"matchCriteriaId": "B07CEFD1-B8EF-4C8D-AA31-A17C7CF5374F"
}
]
}
]
}
],
"references": [
{
"url": "https://insightsoftware.com/trust/security/advisories/redshift-and-athena-driver-vulnerability/",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.magnitude.com/products/data-connectivity",
"source": "cve@mitre.org",
"tags": [
"Product"
]
}
]
}