CVE-2022-28352
Last modified
CVE-2022-28352 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after certain GnuTLS options are changed, which allows man-in-the-middle attackers to spoof a TLS chat server via an arbitrary certificate. NOTE: this only affects situations where weechat.network.gnutls_ca_system or weechat.network.gnutls_ca_user is changed without a WeeChat restart.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after certain GnuTLS options are changed, which allows man-in-the-middle attackers to spoof a TLS chat server via an arbitrary certificate. NOTE: this only affects situations where weechat.network.gnutls_ca_system or weechat.network.gnutls_ca_user is changed without a WeeChat restart.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Weechat | Weechat | >= 3.2, < 3.4.1 |
References
- https://github.com/weechat/weechat/issues/1763Exploit, Issue Tracking, Mitigation, Third Party Advisory
- https://weechat.org/doc/security/WSA-2022-1/Exploit, Vendor Advisory
- https://github.com/weechat/weechat/issues/1763Exploit, Issue Tracking, Mitigation, Third Party Advisory
- https://weechat.org/doc/security/WSA-2022-1/Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-28352?
How severe is CVE-2022-28352?
How do I fix CVE-2022-28352?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-28346An issue was discovered in Django 2.2 before 2.2.28, 3.2 bef…9.8
- CVE-2022-28347A SQL injection issue was discovered in QuerySet.explain() i…9.8
- CVE-2022-28348Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifr…9.8
- CVE-2022-28349Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28…9.8
- CVE-2022-2835A flaw was found in coreDNS. This flaw allows a malicious us…4.4
- CVE-2022-28350Arm Mali GPU Kernel Driver allows improper GPU operations in…9.8
- CVE-2022-28353In the External Redirect Warning Plugin 1.3 for MyBB, the re…6.1
- CVE-2022-28354In the Active Threads Plugin 1.3.0 for MyBB, the activethrea…6.1
- CVE-2022-28355randomUUID in Scala.js before 1.10.0 generates predictable v…7.5
- CVE-2022-28356In the Linux kernel before 5.17.1, a refcount leak bug was f…5.5
- CVE-2022-28357NATS nats-server 2.2.0 through 2.7.4 allows directory traver…9.8
- CVE-2022-28363Reprise License Manager 14.2 is affected by a reflected cros…6.1
Are you affected by CVE-2022-28352?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
