PT-2022-24448 · Archery · Archery

Bit-Sec

·

Published

2022-09-13

·

Updated

2022-10-06

·

CVE-2022-38542

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Archery versions 1.4.0 through 1.8.5
Description The issue is related to a SQL injection vulnerability. It occurs via the ThreadIDs parameter in the "kill session" interface.
Recommendations For versions 1.4.0 through 1.8.5, upgrade to version 1.9.0 or above to resolve the issue. As a temporary workaround, consider restricting access to the kill session interface until the update is applied. Avoid using the ThreadIDs parameter in the affected interface until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-38542

Affected Products

Archery