2024-12-08 03:06:42 +00:00

120 lines
3.9 KiB
JSON

{
"id": "CVE-2022-4428",
"sourceIdentifier": "cna@cloudflare.com",
"published": "2023-01-11T17:15:09.383",
"lastModified": "2024-11-21T07:35:14.653",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching an arbitrary executable on the local machine upon clicking on the \"Send feedback\" option. An attacker with access to the local file system could use a crafted XML config file pointing to a malicious file or set a local path to the executable using Cloudflare Zero Trust Dashboard (for Zero Trust enrolled clients).\n"
},
{
"lang": "es",
"value": "El par\u00e1metro support_uri en el archivo de configuraci\u00f3n local del cliente WARP (mdm.xml) carec\u00eda de la validaci\u00f3n adecuada, lo que permit\u00eda escalar privilegios y lanzar un ejecutable arbitrario en la m\u00e1quina local al hacer clic en la opci\u00f3n \"Enviar comentarios\". Un atacante con acceso al sistema de archivos local podr\u00eda usar un archivo de configuraci\u00f3n XML manipulado que apunte a un archivo malicioso o establecer una ruta local al ejecutable usando Cloudflare Zero Trust Dashboard (para clientes inscritos en Zero Trust)."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cna@cloudflare.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L",
"baseScore": 8.9,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 2.3,
"impactScore": 6.0
},
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"baseScore": 8.0,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 2.1,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "cna@cloudflare.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cloudflare:warp:*:*:*:*:*:windows:*:*",
"versionEndIncluding": "2022.10.106.0",
"matchCriteriaId": "1D88EEFC-CC34-4519-AC8A-7A46F6C8ADF1"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/cloudflare/advisories/security/advisories/GHSA-h3j3-fhqg-66rh",
"source": "cna@cloudflare.com",
"tags": [
"Product",
"Third Party Advisory"
]
},
{
"url": "https://github.com/cloudflare/advisories/security/advisories/GHSA-h3j3-fhqg-66rh",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Product",
"Third Party Advisory"
]
}
]
}