Lucene search

K
cve[email protected]CVE-2022-32550
HistoryJun 15, 2022 - 7:15 p.m.

CVE-2022-32550

2022-06-1519:15:11
web.nvd.nist.gov
1498
agilebits
1password
cve-2022-32550
security issue
malicious server

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

4.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.3%

An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue allowed a malicious server to convince a 1Password app or integration it is communicating with the 1Password service.

Affected configurations

NVD
Node
1password1passwordRange7.07.9.3android
OR
1password1passwordRange7.07.9.5macos
OR
1password1passwordRange7.07.9.6iphone_os
OR
1password1passwordRange7.07.9.829windows
OR
1password1passwordRange8.08.7.1linux
OR
1password1passwordRange8.08.7.1macos
OR
1password1passwordRange8.08.7.1windows
OR
1password1passwordRange8.08.8.0-94iphone_os
OR
1password1passwordRange8.08.8.0-104android
OR
1password1password_in_the_browserRange<2.3.4
OR
1passwordcommand-lineRange2.0.02.3.0
OR
1passwordcommand_line_interfaceRange1.0.01.12.5
OR
1passwordconnectRange<1.5.3
OR
1passwordscim_bridgeRange<2.3.2

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

4.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.3%

Related for CVE-2022-32550