PT-2022-22172 · Mendix · Mendix
Published
2022-07-12
·
Updated
2023-06-29
·
CVE-2022-34466
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mendix Applications using Mendix 9 versions 9.11 through 9.14
Mendix Applications using Mendix 9 version 9.12 versions prior to 9.12.3
Description
An expression injection vulnerability was discovered in the Workflow subsystem of Mendix Runtime. This issue can affect running applications and may allow a malicious user to leak sensitive information in certain configurations.
Recommendations
For Mendix Applications using Mendix 9 versions 9.11 through 9.14, update to version 9.15 or later.
For Mendix Applications using Mendix 9 version 9.12, update to version 9.12.3 or later.
As a temporary workaround, consider restricting access to the Workflow subsystem of Mendix Runtime until a patch is available.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mendix