PT-2022-27460 · Funkwhale · Funkwhale
Fuomag9
·
Published
2022-12-09
·
Updated
2022-12-13
·
CVE-2022-45292
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Funkwhale version 1.2.8
Description
The issue concerns user invites that do not permanently expire after being used for signup. These invites can be used again even after an account associated with the invite has been deleted.
Recommendations
For Funkwhale version 1.2.8, consider temporarily restricting the use of user invites until a patch is available to prevent their reuse after account deletion.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Funkwhale