First published: Thu Oct 27 2022(Updated: )
Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injection. This affects 1.7.0 versions before 1.7.16.1.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Litespeedtech Openlitespeed | >=1.7.0<=1.7.16.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0073 has a high severity rating due to the potential for command injection.
CVE-2022-0073 affects OpenLiteSpeed and LiteSpeed Web Server versions from 1.7.0 to 1.7.16.1.
To fix CVE-2022-0073, upgrade to version 1.7.16.1 or later of OpenLiteSpeed or LiteSpeed Web Server.
CVE-2022-0073 is an improper input validation vulnerability which allows for command injection.
Any users or organizations running the affected versions of OpenLiteSpeed and LiteSpeed Web Server dashboards are impacted by CVE-2022-0073.