PT-2022-22172 · Mendix · Mendix

Published

2022-07-12

·

Updated

2023-06-29

·

CVE-2022-34466

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mendix Applications using Mendix 9 versions 9.11 through 9.14 Mendix Applications using Mendix 9 version 9.12 versions prior to 9.12.3
Description An expression injection vulnerability was discovered in the Workflow subsystem of Mendix Runtime. This issue can affect running applications and may allow a malicious user to leak sensitive information in certain configurations.
Recommendations For Mendix Applications using Mendix 9 versions 9.11 through 9.14, update to version 9.15 or later. For Mendix Applications using Mendix 9 version 9.12, update to version 9.12.3 or later. As a temporary workaround, consider restricting access to the Workflow subsystem of Mendix Runtime until a patch is available.

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2022-34466

Affected Products

Mendix