PT-2022-18698 · Pexip · Pexip Infinity

Published

2022-07-17

·

Updated

2023-08-08

·

CVE-2022-27930

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Pexip Infinity versions prior to 27.3
Description The issue allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed. This can be achieved by exploiting the single-sign-on feature.
Recommendations For versions prior to 27.3, update to version 27.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the single-sign-on feature until a patch is applied.

Fix

Related Identifiers

CVE-2022-27930

Affected Products

Pexip Infinity