Vulnerability Description
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mealie | Mealie | 0.5.5 |
Related Weaknesses (CWE)
References
- http://hkotel.comNot ApplicableURL Repurposed
- http://mealie.comNot ApplicableURL Repurposed
- https://gainsec.com/2022/08/19/cve-2022-34615-cve-2022-34621-cve-2022-34623-cve-Third Party Advisory
- http://hkotel.comNot ApplicableURL Repurposed
- http://mealie.comNot ApplicableURL Repurposed
- https://gainsec.com/2022/08/19/cve-2022-34615-cve-2022-34621-cve-2022-34623-cve-Third Party Advisory
FAQ
What is CVE-2022-34624?
CVE-2022-34624 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
How severe is CVE-2022-34624?
CVE-2022-34624 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-34624?
Check the references section above for vendor advisories and patch information. Affected products include: Mealie Mealie.