2024-12-08 03:06:42 +00:00

107 lines
3.0 KiB
JSON

{
"id": "CVE-2022-45921",
"sourceIdentifier": "cve@mitre.org",
"published": "2022-11-28T21:15:10.747",
"lastModified": "2024-11-21T07:29:57.640",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve any file readable by the user running the FusionAuth process."
},
{
"lang": "es",
"value": "FusionAuth anterior a 1.41.3 permite ver o recuperar un archivo fuera del root de la aplicaci\u00f3n mediante una solicitud HTTP. Para ser espec\u00edfico, un atacante puede ver o recuperar cualquier archivo legible por el usuario que ejecuta el proceso FusionAuth."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:fusionauth:fusionauth:*:*:*:*:*:*:*:*",
"versionStartIncluding": "1.37.0",
"versionEndExcluding": "1.41.3",
"matchCriteriaId": "9E1FF535-F9FA-4576-99AA-F43450B7229E"
}
]
}
]
}
],
"references": [
{
"url": "https://fusionauth.io/docs/v1/tech/release-notes",
"source": "cve@mitre.org",
"tags": [
"Release Notes",
"Vendor Advisory"
]
},
{
"url": "https://github.com/FusionAuth/fusionauth-issues/issues/1983",
"source": "cve@mitre.org",
"tags": [
"Issue Tracking",
"Third Party Advisory"
]
},
{
"url": "https://fusionauth.io/docs/v1/tech/release-notes",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Release Notes",
"Vendor Advisory"
]
},
{
"url": "https://github.com/FusionAuth/fusionauth-issues/issues/1983",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Issue Tracking",
"Third Party Advisory"
]
}
]
}