Vulnerability Description
FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve any file readable by the user running the FusionAuth process.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fusionauth | Fusionauth | >= 1.37.0, < 1.41.3 |
Related Weaknesses (CWE)
References
- https://fusionauth.io/docs/v1/tech/release-notesRelease NotesVendor Advisory
- https://github.com/FusionAuth/fusionauth-issues/issues/1983Issue TrackingThird Party Advisory
- https://fusionauth.io/docs/v1/tech/release-notesRelease NotesVendor Advisory
- https://github.com/FusionAuth/fusionauth-issues/issues/1983Issue TrackingThird Party Advisory
FAQ
What is CVE-2022-45921?
CVE-2022-45921 is a vulnerability with a CVSS score of 7.5 (HIGH). FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve any file readable by...
How severe is CVE-2022-45921?
CVE-2022-45921 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-45921?
Check the references section above for vendor advisories and patch information. Affected products include: Fusionauth Fusionauth.