SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-38131

The vulnerability could allow an attacker to redirect users to malicious websites.

MEDIUM 6.1EPSS 1.66%

Does this matter?

Lower severity and a low EPSS score (1.66%). Track it; it rarely justifies an emergency change on its own.

Description

RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.66% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-601
Affected
rstudio/connect
Source
vulnreport@tenable.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.