CVE-2022-36006
Last modified
CVE-2022-36006 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execution (RCE) vulnerability in the Arvados Workbench allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. EPSS estimates a 1.26% chance of exploitation in the next 30 days.
Description
Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execution (RCE) vulnerability in the Arvados Workbench allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. This exists in all versions up to 2.4.1 and is fixed in 2.4.2. This vulnerability is specific to the Ruby on Rails Workbench application (“Workbench 1”). We do not believe any other Arvados components, including the TypesScript browser-based Workbench application (“Workbench 2”) or API Server, are vulnerable to this attack. For versions of Arvados earlier than 2.4.2: remove the Ruby-based "Workbench 1" app ("apt-get remove arvados-workbench") from your installation as a workaround.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arvados | Arvados | < 2.4.2 |
References
- https://arvados.org/release-notes/2.4.2/Vendor Advisory
- https://dev.arvados.org/issues/19316Issue Tracking, Vendor Advisory
- https://github.com/arvados/arvados/security/advisories/GHSA-8867-q4xf-cqgmThird Party Advisory
- https://arvados.org/release-notes/2.4.2/Vendor Advisory
- https://dev.arvados.org/issues/19316Issue Tracking, Vendor Advisory
- https://github.com/arvados/arvados/security/advisories/GHSA-8867-q4xf-cqgmThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-36006?
How severe is CVE-2022-36006?
How do I fix CVE-2022-36006?
Are you affected by CVE-2022-36006?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
