Vulnerability Description
Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-privileged user.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://mender.io/blog/cve-2022-45929-cve-2022-41324-improper-access-control-for
- https://northern.tech
- https://mender.io/blog/cve-2022-45929-cve-2022-41324-improper-access-control-for
- https://northern.tech
FAQ
What is CVE-2022-45929?
CVE-2022-45929 is a vulnerability with a CVSS score of 8.8 (HIGH). Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-...
How severe is CVE-2022-45929?
CVE-2022-45929 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-45929?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.