VulnerabilityModified
CVE-2022-34621
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.
MEDIUM 6.5EPSS 1.03%
Does this matter?
Lower severity and a low EPSS score (1.03%). Track it; it rarely justifies an emergency change on its own.
Description
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.03% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Affected
- mealie/mealie
- Source
- cve@mitre.org
References
- https://cwe.mitre.org/data/definitions/639.htmlThird Party Advisory
- https://docs.mealie.io/changelog/v0.5.6/Release Notes, Third Party Advisory
- https://gainsec.com/2022/08/19/cve-2022-34615-cve-2022-34621-cve-2022-34623-cve-2022-34624/Third Party Advisory
- https://hub.docker.com/r/hkotel/mealieProduct, Third Party Advisory
- https://portswigger.net/web-security/access-control/idorThird Party Advisory
- https://cwe.mitre.org/data/definitions/639.htmlThird Party Advisory
- https://docs.mealie.io/changelog/v0.5.6/Release Notes, Third Party Advisory
- https://gainsec.com/2022/08/19/cve-2022-34615-cve-2022-34621-cve-2022-34623-cve-2022-34624/Third Party Advisory
- https://hub.docker.com/r/hkotel/mealieProduct, Third Party Advisory
- https://portswigger.net/web-security/access-control/idorThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.