CVE-2022-47551
Last modified
CVE-2022-47551 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The root cause of the issue is the Apiman project's accidental acceptance of a large contribution that was not fully compatible with the security model of Apiman versions before 3.0.0.Final. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The root cause of the issue is the Apiman project's accidental acceptance of a large contribution that was not fully compatible with the security model of Apiman versions before 3.0.0.Final. Because of this, 3.0.0.Final is not affected by the vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apiman | Apiman | >= 1.5.7, <= 2.2.3 |
References
- https://www.apiman.io/blog/permissions-bypass-disclosure/Vendor Advisory
- https://www.github.com/apiman/apimanThird Party Advisory
- https://www.apiman.io/blog/permissions-bypass-disclosure/Vendor Advisory
- https://www.github.com/apiman/apimanThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-47551?
How severe is CVE-2022-47551?
How do I fix CVE-2022-47551?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-47542Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect A…8.8
- CVE-2022-47543An issue was discovered in Siren Investigate before 12.1.7. …5.3
- CVE-2022-47544An issue was discovered in Siren Investigate before 12.1.7. …9.8
- CVE-2022-47547GossipSub 1.1, as used for Ethereum 2.0, allows a peer to ma…5.3
- CVE-2022-47549An unprotected memory-access operation in optee_os in Truste…6.4
- CVE-2022-4755A vulnerability was found in FlatPress and classified as pro…6.1
- CVE-2022-47553Incorrect authorisation in ekorCCP and ekorRCI, which could …7.5
- CVE-2022-47554Exposure of sensitive information in ekorCCP and ekorRCI, po…7.5
- CVE-2022-47555Operating system command injection in ekorCCP and ekorRCI, w…8.8
- CVE-2022-47556Uncontrolled resource consumption in ekorRCI, allowing an at…6.5
- CVE-2022-47557Vulnerability in ekorCCP and ekorRCI that could allow an att…6.1
- CVE-2022-47558Devices ekorCCP and ekorRCI are vulnerable due to access to …9.8
Are you affected by CVE-2022-47551?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
