Vulnerability Description
The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that captured authentication requests. This vulnerability is resolved in osisoft-pi-web-connector version 0.44.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Osisoft-Pi-Web-Connector Project | Osisoft-Pi-Web-Connector | >= 0.15.0, < 0.44.0 |
Related Weaknesses (CWE)
References
- https://github.com/palantir/security-bulletins/blob/main/PLTRSEC-2022-03.mdThird Party Advisory
- https://github.com/palantir/security-bulletins/blob/main/PLTRSEC-2022-03.mdThird Party Advisory
FAQ
What is CVE-2022-27893?
CVE-2022-27893 is a vulnerability with a CVSS score of 4.2 (MEDIUM). The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that captured authentication requests. This vulnerability is resolved in osisoft-pi-we...
How severe is CVE-2022-27893?
CVE-2022-27893 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-27893?
Check the references section above for vendor advisories and patch information. Affected products include: Osisoft-Pi-Web-Connector Project Osisoft-Pi-Web-Connector.