Vulnerability Description
Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Patched Versions are 3.5.3, 3.4.7, and 2.12.6.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ironmansoftware | Powershell Universal | >= 2.0.0, < 2.12.6 |
Related Weaknesses (CWE)
References
- https://blog.ironmansoftware.com/psu-2022-11-cve/Vendor Advisory
- https://docs.powershelluniversal.com/changelogRelease NotesVendor Advisory
- https://ironmansoftware.comVendor Advisory
- https://blog.ironmansoftware.com/psu-2022-11-cve/Vendor Advisory
- https://docs.powershelluniversal.com/changelogRelease NotesVendor Advisory
- https://ironmansoftware.comVendor Advisory
FAQ
What is CVE-2022-45183?
CVE-2022-45183 is a vulnerability with a CVSS score of 8.8 (HIGH). Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Pa...
How severe is CVE-2022-45183?
CVE-2022-45183 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-45183?
Check the references section above for vendor advisories and patch information. Affected products include: Ironmansoftware Powershell Universal.