#VU66675 Information disclosure in Mealie - CVE-2022-34623

 

#VU66675 Information disclosure in Mealie - CVE-2022-34623

Published: August 22, 2022


Vulnerability identifier: #VU66675
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-34623
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mealie
Software vendor:
hay-kot

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a flaw in the authentication process. A remote attacker can send a specially crafted request using improper username and password and gain unauthorized access to sensitive information on the system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links