CVE-2022-4879
A vulnerability was found in Forged Alliance Forever up to 3746.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to address this issue. The patch is named 6880971bd3d73d942384aff62d53058c206ce644. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217555.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285
- Affected
- forged alliance forever project/forged alliance forever
- Source
- cna@vuldb.com
References
- https://github.com/FAForever/fa/commit/6880971bd3d73d942384aff62d53058c206ce644Patch
- https://github.com/FAForever/fa/pull/4398Patch
- https://github.com/FAForever/fa/releases/tag/3747Release Notes
- https://vuldb.com/?ctiid.217555Permissions Required
- https://vuldb.com/?id.217555Third Party Advisory
- https://github.com/FAForever/fa/commit/6880971bd3d73d942384aff62d53058c206ce644Patch
- https://github.com/FAForever/fa/pull/4398Patch
- https://github.com/FAForever/fa/releases/tag/3747Release Notes
- https://vuldb.com/?ctiid.217555Permissions Required
- https://vuldb.com/?id.217555Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.