PT-2022-6548 · Rdiffweb · Rdiffweb

Published

2022-12-22

·

Updated

2023-07-17

·

CVE-2022-4722

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rdiffweb versions prior to 2.5.5
Description The issue is related to a primary weakness in the rdiffweb GitHub repository, allowing for authentication bypass. This weakness is due to the username field not being unique to users, enabling exploitation of primary key logic by creating the same name with different combinations, which may allow unauthorized access.
Recommendations For versions prior to 2.5.5, update to version 2.5.5 or later to resolve the authentication bypass issue. As a temporary workaround, consider restricting access to the username field to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02318
CVE-2022-4722
GHSA-WF33-6X33-WCF9
PYSEC-2022-43008

Affected Products

Rdiffweb