CVE-2022-24309
Last modified
CVE-2022-24309 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A vulnerability has been identified in Mendix Runtime V7 (All versions < V7.23.29), Mendix Runtime V8 (All versions < V8.18.16), Mendix Runtime V9 (All versions < V9.13 only with Runtime Custom Setting *DataStorage.UseNewQueryHandler* set to False). If an entity has an association readable by the user, then in some cases, Mendix Runtime may not apply checks for XPath constraints that parse said associations, within apps running on affected versions. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in Mendix Runtime V7 (All versions < V7.23.29), Mendix Runtime V8 (All versions < V8.18.16), Mendix Runtime V9 (All versions < V9.13 only with Runtime Custom Setting *DataStorage.UseNewQueryHandler* set to False). If an entity has an association readable by the user, then in some cases, Mendix Runtime may not apply checks for XPath constraints that parse said associations, within apps running on affected versions. A malicious user could use this to dump and manipulate sensitive data.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mendix | Mendix | < 7.23.29 |
| Mendix | Mendix | >= 8.0.0, < 8.18.16 |
| Mendix | Mendix | >= 9.0.0, < 9.13 |
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-148641.pdfMitigation, Release Notes, Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-148641.pdfMitigation, Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-24309?
How severe is CVE-2022-24309?
How do I fix CVE-2022-24309?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-24303Pillow before 9.0.1 allows attackers to delete files because…9.1
- CVE-2022-24304Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-24305Zoho ManageEngine SharePoint Manager Plus before 4329 is vul…9.8
- CVE-2022-24306Zoho ManageEngine SharePoint Manager Plus before 4329 allows…9.8
- CVE-2022-24307Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect a…9.8
- CVE-2022-24308Automox Agent prior to version 37 on Windows and Linux and V…5.5
- CVE-2022-2431The Download Manager plugin for WordPress is vulnerable to a…8.8
- CVE-2022-24310A CWE-190: Integer Overflow or Wraparound vulnerability exis…9.8
- CVE-2022-24311A CWE-22: Improper Limitation of a Pathname to a Restricted …9.8
- CVE-2022-24312A CWE-22: Improper Limitation of a Pathname to a Restricted …9.8
- CVE-2022-24313A CWE-120: Buffer Copy without Checking Size of Input vulner…9.8
- CVE-2022-24314A CWE-125: Out-of-bounds Read vulnerability exists that coul…7.5
Are you affected by CVE-2022-24309?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
