Vulnerability Description
An access control issue in aleksis/core/util/auth_helpers.py: ClientProtectedResourceMixin of AlekSIS-Core v2.8.1 and below allows attackers to access arbitrary scopes if no allowed scopes are specifically set.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aleksis | Aleksis | < 2.8.2 |
References
- https://aleksis.org/2022-05-04_advisory.htmlBroken LinkVendor Advisory
- https://edugit.org/AlekSIS/official/AlekSIS-Core/-/issues/688Issue TrackingThird Party Advisory
- https://aleksis.org/2022-05-04_advisory.htmlBroken LinkVendor Advisory
- https://edugit.org/AlekSIS/official/AlekSIS-Core/-/issues/688Issue TrackingThird Party Advisory
FAQ
What is CVE-2022-29773?
CVE-2022-29773 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An access control issue in aleksis/core/util/auth_helpers.py: ClientProtectedResourceMixin of AlekSIS-Core v2.8.1 and below allows attackers to access arbitrary scopes if no allowed scopes are specifi...
How severe is CVE-2022-29773?
CVE-2022-29773 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-29773?
Check the references section above for vendor advisories and patch information. Affected products include: Aleksis Aleksis.