Lucene search

K
cveGitHub_MCVE-2022-23644
HistoryFeb 16, 2022 - 7:15 p.m.

CVE-2022-23644

2022-02-1619:15:09
CWE-918
GitHub_M
web.nvd.nist.gov
78
bookwyrm
decentralized
social network
ssrf
vulnerability
patch
upgrade
registration
security alert
nvd

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

42.8%

BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable to a server-side request forgery attack. Any BookWyrm instance running a version prior to v0.3.0 is susceptible to attack from a logged-in user. The problem has been patched and administrators should upgrade to version 0.3.0 As a workaround, BookWyrm instances can close registration and limit members to trusted individuals.

Affected configurations

Nvd
Vulners
Node
joinbookwyrmbookwyrmRange<0.3.0
VendorProductVersionCPE
joinbookwyrmbookwyrm*cpe:2.3:a:joinbookwyrm:bookwyrm:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "bookwyrm",
    "vendor": "bookwyrm-social",
    "versions": [
      {
        "status": "affected",
        "version": "< 0.3.0"
      }
    ]
  }
]

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

42.8%

Related for CVE-2022-23644