{"api_version":"1","generated_at":"2026-07-23T12:47:25+00:00","cve":"CVE-2022-41708","urls":{"html":"https://cve.report/CVE-2022-41708","api":"https://cve.report/api/cve/CVE-2022-41708.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-41708","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-41708"},"summary":{"title":"CVE-2022-41708","description":"Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate permissions correctly.","state":"PUBLIC","assigner":"help@fluidattacks.com","published_at":"2022-10-19 19:15:00","updated_at":"2022-10-21 17:59:00"},"problem_types":["CWE-281"],"metrics":[],"references":[{"url":"https://fluidattacks.com/advisories/tiesto/","name":"https://fluidattacks.com/advisories/tiesto/","refsource":"MISC","tags":[],"title":"relatedcode/Messenger 7bcd20b - Broken Access Control | Fluid Attacks","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/relatedcode/Messenger","name":"https://github.com/relatedcode/Messenger","refsource":"MISC","tags":[],"title":"GitHub - relatedcode/Messenger: Open source, native iOS Messenger, with realtime chat conversations (full offline support).","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-41708","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41708","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"41708","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"relatedcode","cpe5":"messenger","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2022-41708","ASSIGNER":"help@fluidattacks.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"relatedcode/Messenger","version":{"version_data":[{"version_value":"7bcd20b"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper authorization control for web services"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://github.com/relatedcode/Messenger","url":"https://github.com/relatedcode/Messenger"},{"refsource":"MISC","name":"https://fluidattacks.com/advisories/tiesto/","url":"https://fluidattacks.com/advisories/tiesto/"}]},"description":{"description_data":[{"lang":"eng","value":"Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate permissions correctly."}]}},"nvd":{"publishedDate":"2022-10-19 19:15:00","lastModifiedDate":"2022-10-21 17:59:00","problem_types":["CWE-281"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:relatedcode:messenger:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}