Lucene search

K
cvelistApacheCVELIST:CVE-2022-34158
HistoryAug 04, 2022 - 6:16 a.m.

CVE-2022-34158 User Group Privilege Escalation

2022-08-0406:16:11
apache
www.cve.org
4
csrf vulnerability
apache jspwiki
user group privilege escalation

AI Score

9.1

Confidence

High

EPSS

0.004

Percentile

73.4%

A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker’s account. Further examination of this issue established that it could also be used to modify the email associated with the attacked account, and then a reset password request from the login page.

CNA Affected

[
  {
    "product": "Apache JSPWiki",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "Apache JSPWiki up to 2.11.2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

9.1

Confidence

High

EPSS

0.004

Percentile

73.4%