Lucene search

K
cve@huntrdevCVE-2022-3423
HistoryOct 07, 2022 - 11:15 a.m.

CVE-2022-3423

2022-10-0711:15:10
CWE-770
@huntrdev
web.nvd.nist.gov
49
6
cve-2022-3423
github repository
nocodb
resource allocation
security vulnerability

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:H

EPSS

0.001

Percentile

31.9%

Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0.

Affected configurations

Nvd
Node
xgenecloudnocodbRange<0.92.0
VendorProductVersionCPE
xgenecloudnocodb*cpe:2.3:a:xgenecloud:nocodb:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "nocodb/nocodb",
    "vendor": "nocodb",
    "versions": [
      {
        "lessThan": "0.92.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:H

EPSS

0.001

Percentile

31.9%