SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-2653

With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environment variable used by the web server that includes database credentials.

MEDIUM 6.5EPSS 0.96%

Does this matter?

Lower severity and a low EPSS score (0.96%). Track it; it rarely justifies an emergency change on its own.

Description

With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environment variable used by the web server that includes database credentials. If the web server user is root, an attacker will be able to read any file in the system.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.96% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
planka/planka
Source
security@huntr.dev

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.