PT-2022-24872 · Unknown+2 · Zoneminder+2

Published

2022-10-07

·

Updated

2023-11-30

·

CVE-2022-39289

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ZoneMinder (affected versions not specified)
Description The issue concerns the ZoneMinder API, which exposes database log contents to users without privileges. It also allows for the insertion, modification, and deletion of logs without system privileges. Users are advised to upgrade as soon as possible.
Recommendations For all affected versions, users are advised to upgrade as soon as possible. As a temporary workaround for users unable to upgrade, consider disabling database logging to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Missing Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2858
ALT-PU-2022-2978
ALT-PU-2023-7284
CVE-2022-39289
GHSA-MPCX-3GVH-9488

Affected Products

Alt Linux
Debian
Zoneminder