CVE-2022-29174
Last modified
CVE-2022-29174 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, a malicious actor who knows an account email address/username and full name specified in the database is capable of guessing the password reset token. EPSS estimates a 1.29% chance of exploitation in the next 30 days.
Description
countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, a malicious actor who knows an account email address/username and full name specified in the database is capable of guessing the password reset token. The actor may use this information to reset the password and take over the account. The problem has been patched in Countly Server version 22.03.7 for servers using the new user interface and in 21.11.4 for servers using the old user interface.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Count | Countly Server | < 21.11.4 |
| Count | Countly Server | >= 22.03, < 22.03.7 |
References
- https://github.com/Countly/countly-server/commit/2bfa1ee1fa46e9bb007cf8687ad197ab9c604999Patch, Third Party Advisory
- https://github.com/Countly/countly-server/security/advisories/GHSA-98vh-wqw5-p23vPatch, Third Party Advisory
- https://github.com/Countly/countly-server/commit/2bfa1ee1fa46e9bb007cf8687ad197ab9c604999Patch, Third Party Advisory
- https://github.com/Countly/countly-server/security/advisories/GHSA-98vh-wqw5-p23vPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-29174?
How severe is CVE-2022-29174?
How do I fix CVE-2022-29174?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-29168Wire is a secure messaging application. Wire is vulnerable t…6.1
- CVE-2022-29169BigBlueButton is an open source web conferencing system. Ver…7.5
- CVE-2022-29170Grafana is an open-source platform for monitoring and observ…8.5
- CVE-2022-29171Sourcegraph is a fast and featureful code search and navigat…7.2
- CVE-2022-29172Auth0 is an authentication broker that supports both social …6.1
- CVE-2022-29173go-tuf is a Go implementation of The Update Framework (TUF).…8.8
- CVE-2022-29175Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-29176Rubygems is a package registry used to supply software for t…7.5
- CVE-2022-29177Go Ethereum is the official Golang implementation of the Eth…5.9
- CVE-2022-29178Cilium is open source software for providing and securing ne…8.2
- CVE-2022-29179Cilium is open source software for providing and securing ne…8.2
- CVE-2022-29180A vulnerability in which attackers could forge HTTP requests…9.8
Are you affected by CVE-2022-29174?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
