CVE-2022-0073: Authenticated Remote Code Execution in OpenLiteSpeed Web Server
Published Oct 27, 2022
·Updated
Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injection. This affects 1.7.0 versions before 1.7.16.1.
Affected Software
1 affected component
Litespeedtech Openlitespeed>=1.7.0<=1.7.16.1
Event History
Oct 27, 2022
CVE Published
via MITRE·07:30 PM
Data Sourced
via MITRE·07:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-0073?
CVE-2022-0073 has a high severity rating due to the potential for command injection.
2
Which versions are affected by CVE-2022-0073?
CVE-2022-0073 affects OpenLiteSpeed and LiteSpeed Web Server versions from 1.7.0 to 1.7.16.1.
3
How do I fix CVE-2022-0073?
To fix CVE-2022-0073, upgrade to version 1.7.16.1 or later of OpenLiteSpeed or LiteSpeed Web Server.
4
What type of vulnerability is CVE-2022-0073?
CVE-2022-0073 is an improper input validation vulnerability which allows for command injection.
5
Who is impacted by CVE-2022-0073?
Any users or organizations running the affected versions of OpenLiteSpeed and LiteSpeed Web Server dashboards are impacted by CVE-2022-0073.