VulnerabilityModified
CVE-2022-24865
HumHub is an Open Source Enterprise Social Network.
MEDIUM 6.5EPSS 1.24%
Does this matter?
Lower severity and a low EPSS score (1.24%). Track it; it rarely justifies an emergency change on its own.
Description
HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`. It is recommended that the HumHub is upgraded to 1.11.0, 1.10.4 or 1.9.4. There are no known workarounds for this issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.24% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-863
- Affected
- humhub/humhub
- Source
- security-advisories@github.com
References
- https://github.com/humhub/humhub/commit/eb83de20aaecc559ab77a44a6179646a99607e33Patch, Third Party Advisory
- https://github.com/humhub/humhub/security/advisories/GHSA-2h35-f226-3f57Third Party Advisory
- https://huntr.dev/bounties/89d996a2-de30-4261-8e3f-98e54cb25f76/Exploit, Patch, Third Party Advisory
- https://github.com/humhub/humhub/commit/eb83de20aaecc559ab77a44a6179646a99607e33Patch, Third Party Advisory
- https://github.com/humhub/humhub/security/advisories/GHSA-2h35-f226-3f57Third Party Advisory
- https://huntr.dev/bounties/89d996a2-de30-4261-8e3f-98e54cb25f76/Exploit, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.