CVE-2022-23655
Last modified
CVE-2022-23655 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatures. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatures. As a result non-authoritative gateway servers may be used to exfiltrate user private keys. Users are advised to upgrade their installations to build 474 or v1.1.10. The only known workaround is to manually apply the patch (e3b455ad587282f0fbcb7763c6d9c3d000ca1e6a) which adds server signature validation.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Octobercms | October | < 1.0.475 |
| Octobercms | October | >= 1.1.0, < 1.1.11 |
References
- https://github.com/octobercms/october/commit/e3b455ad587282f0fbcb7763c6d9c3d000ca1e6aPatch, Third Party Advisory
- https://github.com/octobercms/october/security/advisories/GHSA-53m6-44rc-h2q5Patch, Third Party Advisory
- https://github.com/octobercms/october/commit/e3b455ad587282f0fbcb7763c6d9c3d000ca1e6aPatch, Third Party Advisory
- https://github.com/octobercms/october/security/advisories/GHSA-53m6-44rc-h2q5Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-23655?
How severe is CVE-2022-23655?
How do I fix CVE-2022-23655?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-2365Cross-site Scripting (XSS) - Stored in GitHub repository zad…5.4
- CVE-2022-23650Netmaker is a platform for creating and managing virtual ove…8.8
- CVE-2022-23651b2-sdk-python is a python library to access cloud storage pr…4.7
- CVE-2022-23652capsule-proxy is a reverse proxy for Capsule Operator which …8.8
- CVE-2022-23653B2 Command Line Tool is the official command line tool for t…4.7
- CVE-2022-23654Wiki.js is a wiki app built on Node.js. In affected versions…6.5
- CVE-2022-23656Zulip is an open source team chat app. The `main` developmen…5.4
- CVE-2022-23657A remote authentication bypass vulnerability was discovered …10
- CVE-2022-23658A remote authentication bypass vulnerability was discovered …10
- CVE-2022-23659A remote reflected cross site scripting (xss) vulnerability …6.1
- CVE-2022-2366Incorrect default configuration for trusted IP header in Mat…5.3
- CVE-2022-23660A remote authentication bypass vulnerability was discovered …10
Are you affected by CVE-2022-23655?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
