CVE-2022-41708
Summary
| CVE | CVE-2022-41708 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-19 19:15:00 UTC |
| Updated | 2022-10-21 17:59:00 UTC |
| Description | Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate permissions correctly. |
Risk And Classification
Problem Types: CWE-281
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Relatedcode | Messenger | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| relatedcode/Messenger 7bcd20b - Broken Access Control | Fluid Attacks | MISC | fluidattacks.com | |
| GitHub - relatedcode/Messenger: Open source, native iOS Messenger, with realtime chat conversations (full offline support). | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.