Lucene search

K
cveJpcertCVE-2022-41799
HistoryOct 24, 2022 - 2:15 p.m.

CVE-2022-41799

2022-10-2414:15:52
jpcert
web.nvd.nist.gov
30
2
cve-2022-41799
growi
vulnerability
access control
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

39.9%

Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) allows a remote authenticated attacker to bypass access restriction and download the markdown data from the pages set to private by the other users.

Affected configurations

Nvd
Node
weseekgrowiRange4.0.0–4.5.25
OR
weseekgrowiRange5.0.0–5.1.4
VendorProductVersionCPE
weseekgrowi*cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "WESEEK, Inc.",
    "product": "GROWI v5 series and v4 series",
    "versions": [
      {
        "version": "versions prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series)",
        "status": "affected"
      }
    ]
  }
]

Social References

More

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

39.9%

Related for CVE-2022-41799