Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31013

Опубликовано: 31 мая 2022
Источник: nvd
CVSS3: 9.1
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the access token, resulting in authentication bypass. The function this.authProvider.verifyAccessKey is an async function, as the code is not using await to wait for the verification result. Every time the function responds back with success, along with an unhandled exception if the token is invalid. A patch is available in version 2.6.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:chat_server_project:chat_server:*:*:*:*:*:*:*:*
Версия от 2.3.2 (включая) до 2.6.0 (исключая)

EPSS

Процентиль: 65%
0.00495
Низкий

9.1 Critical

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287
CWE-20

EPSS

Процентиль: 65%
0.00495
Низкий

9.1 Critical

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287
CWE-20