Vulnerability Description
Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pexip | Pexip Infinity | >= 27.0, < 27.3 |
References
- https://docs.pexip.com/admin/security_bulletins.htm#CVE-2022-27930Vendor Advisory
- https://docs.pexip.com/admin/security_bulletins.htm#CVE-2022-27930Vendor Advisory
FAQ
What is CVE-2022-27930?
CVE-2022-27930 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed.
How severe is CVE-2022-27930?
CVE-2022-27930 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-27930?
Check the references section above for vendor advisories and patch information. Affected products include: Pexip Pexip Infinity.