Vulnerability Description
Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mealie | Mealie | 0.5.5 |
Related Weaknesses (CWE)
References
- https://cwe.mitre.org/data/definitions/521.htmlThird Party Advisory
- https://docs.mealie.io/changelog/v0.5.6/Release NotesThird Party Advisory
- https://gainsec.com/2022/08/19/cve-2022-34615-cve-2022-34621-cve-2022-34623-cve-Third Party Advisory
- https://hub.docker.com/r/hkotel/mealieProductThird Party Advisory
- https://cwe.mitre.org/data/definitions/521.htmlThird Party Advisory
- https://docs.mealie.io/changelog/v0.5.6/Release NotesThird Party Advisory
- https://gainsec.com/2022/08/19/cve-2022-34615-cve-2022-34621-cve-2022-34623-cve-Third Party Advisory
- https://hub.docker.com/r/hkotel/mealieProductThird Party Advisory
FAQ
What is CVE-2022-34615?
CVE-2022-34615 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.
How severe is CVE-2022-34615?
CVE-2022-34615 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-34615?
Check the references section above for vendor advisories and patch information. Affected products include: Mealie Mealie.