Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-34466

Опубликовано: 12 июл. 2022
Источник: nvd
CVSS3: 6.5
CVSS2: 3.5
EPSS Низкий

Описание

A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.3). An expression injection vulnerability was discovered in the Workflow subsystem of Mendix Runtime, that can affect the running applications. The vulnerability could allow a malicious user to leak sensitive information in a certain configuration.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*
Версия от 9.11.0 (включая) до 9.15.0 (исключая)

EPSS

Процентиль: 72%
0.00707
Низкий

6.5 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-74
CWE-917

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.3). An expression injection vulnerability was discovered in the Workflow subsystem of Mendix Runtime, that can affect the running applications. The vulnerability could allow a malicious user to leak sensitive information in a certain configuration.

EPSS

Процентиль: 72%
0.00707
Низкий

6.5 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-74
CWE-917