Lucene search

K
cveGitHub_MCVE-2023-22737
HistoryJan 28, 2023 - 12:15 a.m.

CVE-2023-22737

2023-01-2800:15:08
CWE-862
CWE-280
GitHub_M
web.nvd.nist.gov
64
cve-2023
wire-server
conversation
bot
permissions check
security vulnerability

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

44.8%

wire-server provides back end services for Wire, a team communication and collaboration platform. Prior to version 2022-12-09, every member of a Conversation can remove a Bot from a Conversation due to a missing permissions check. Only Conversation admins should be able to remove Bots. Regular Conversations are not allowed to do so. The issue is fixed in wire-server 2022-12-09 and is already deployed on all Wire managed services. On-premise instances of wire-server need to be updated to 2022-12-09/Chart 4.29.0, so that their backends are no longer affected. There are no known workarounds.

Affected configurations

Nvd
Vulners
Node
wirewireRange<2022-12-09
VendorProductVersionCPE
wirewire*cpe:2.3:a:wire:wire:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "wireapp",
    "product": "wire-server",
    "versions": [
      {
        "version": "< 2022-12-09",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

44.8%

Related for CVE-2023-22737