CVE-2022-4018
Published on: Not Yet Published
Last Modified on: 11/18/2022 04:47:00 AM UTC
CVE-2022-4018 - advisory for 5340c2f6-0252-40f6-8929-cca5d64958a5
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Rdiffweb from Ikus-soft contain the following vulnerability:
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
- CVE-2022-4018 has been assigned by
sec[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
ikus060 - ikus060/rdiffweb version < 2.5.0a6
CVSS3 Score: 4.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | LOW |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Define idle and absolute session timeout with agressive default to pr… · ikus060/rdiffweb@f2a32f2 · GitHub | github.com text/html |
![]() |
huntr: Page not found | huntr.dev text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Ikus-soft | Rdiffweb | 2.5.0 | alpha1 | All | All |
Application | Ikus-soft | Rdiffweb | 2.5.0 | alpha2 | All | All |
Application | Ikus-soft | Rdiffweb | 2.5.0 | alpha3 | All | All |
Application | Ikus-soft | Rdiffweb | 2.5.0 | alpha4 | All | All |
Application | Ikus-soft | Rdiffweb | 2.5.0 | alpha5 | All | All |
Application | Ikus-soft | Rdiffweb | All | All | All | All |
- cpe:2.3:a:ikus-soft:rdiffweb:2.5.0:alpha1:*:*:*:*:*:*:
- cpe:2.3:a:ikus-soft:rdiffweb:2.5.0:alpha2:*:*:*:*:*:*:
- cpe:2.3:a:ikus-soft:rdiffweb:2.5.0:alpha3:*:*:*:*:*:*:
- cpe:2.3:a:ikus-soft:rdiffweb:2.5.0:alpha4:*:*:*:*:*:*:
- cpe:2.3:a:ikus-soft:rdiffweb:2.5.0:alpha5:*:*:*:*:*:*:
- cpe:2.3:a:ikus-soft:rdiffweb:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-4018 : Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6… twitter.com/i/web/status/1… | 2022-11-16 12:25:47 |
![]() |
CVE-2022-4018 | 2022-11-16 13:38:43 |