Vulnerability Description
The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which allows a remote attacker with administrator privilege to create, delete, update, and display files outside of the configuration directory via a crafted HTTP request to particular endpoints in the web server. Patched Versions are 3.5.3 and 3.4.7.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ironmansoftware | Powershell Universal | >= 3.0.0, < 3.4.7 |
Related Weaknesses (CWE)
References
- https://blog.ironmansoftware.com/psu-2022-11-cve/Vendor Advisory
- https://docs.powershelluniversal.com/changelogRelease NotesVendor Advisory
- https://ironmansoftware.comVendor Advisory
- https://blog.ironmansoftware.com/psu-2022-11-cve/Vendor Advisory
- https://docs.powershelluniversal.com/changelogRelease NotesVendor Advisory
- https://ironmansoftware.comVendor Advisory
FAQ
What is CVE-2022-45184?
CVE-2022-45184 is a vulnerability with a CVSS score of 7.2 (HIGH). The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which allows a remote attacker with administrator privilege...
How severe is CVE-2022-45184?
CVE-2022-45184 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-45184?
Check the references section above for vendor advisories and patch information. Affected products include: Ironmansoftware Powershell Universal.