{"api_version":"1","generated_at":"2026-05-28T03:27:53+00:00","cve":"CVE-2022-3741","urls":{"html":"https://cve.report/CVE-2022-3741","api":"https://cve.report/api/cve/CVE-2022-3741.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-3741","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-3741"},"summary":{"title":"CVE-2022-3741","description":"Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to separate accounts that are generated and waiting for email verification. \\n\\nFor the sign in directories, it is possible to brute force login attempts to either login portal, which could lead to account compromise.","state":"PUBLIC","assigner":"security@huntr.dev","published_at":"2022-10-28 13:15:00","updated_at":"2022-11-01 18:45:00"},"problem_types":["CWE-307"],"metrics":[],"references":[{"url":"https://huntr.dev/bounties/46f6e07e-f438-4540-938a-510047f987d0","name":"https://huntr.dev/bounties/46f6e07e-f438-4540-938a-510047f987d0","refsource":"CONFIRM","tags":[],"title":"Chatwoot's Misconfigured Rack_Attack.rb Does Not Appropriately Protect Against Brute Force Attacks  vulnerability found in chatwoot","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/chatwoot/chatwoot/commit/9525d4f0346a2fdac13a0253f9180d20104a72d3","name":"https://github.com/chatwoot/chatwoot/commit/9525d4f0346a2fdac13a0253f9180d20104a72d3","refsource":"MISC","tags":[],"title":"chore: Improve rack-attack configuration (#5389) · chatwoot/chatwoot@9525d4f · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-3741","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-3741","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"3741","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"chatwoot","cpe5":"chatwoot","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@huntr.dev","ID":"CVE-2022-3741","STATE":"PUBLIC","TITLE":"Improper Restriction of Excessive Authentication Attempts in chatwoot/chatwoot"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"chatwoot/chatwoot","version":{"version_data":[{"version_affected":"<","version_value":"v2.10.0"}]}}]},"vendor_name":"chatwoot"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to separate accounts that are generated and waiting for email verification. \\n\\nFor the sign in directories, it is possible to brute force login attempts to either login portal, which could lead to account compromise."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":9.4,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-307 Improper Restriction of Excessive Authentication Attempts"}]}]},"references":{"reference_data":[{"name":"https://huntr.dev/bounties/46f6e07e-f438-4540-938a-510047f987d0","refsource":"CONFIRM","url":"https://huntr.dev/bounties/46f6e07e-f438-4540-938a-510047f987d0"},{"name":"https://github.com/chatwoot/chatwoot/commit/9525d4f0346a2fdac13a0253f9180d20104a72d3","refsource":"MISC","url":"https://github.com/chatwoot/chatwoot/commit/9525d4f0346a2fdac13a0253f9180d20104a72d3"}]},"source":{"advisory":"46f6e07e-f438-4540-938a-510047f987d0","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-10-28 13:15:00","lastModifiedDate":"2022-11-01 18:45:00","problem_types":["CWE-307"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:chatwoot:chatwoot:*:*:*:*:*:*:*:*","versionEndExcluding":"2.10.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}