CVE-2022-0664: Use of Hard-coded Cryptographic Key in gravitl/netmaker
Published Feb 18, 2022
·Updated
Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.
Affected Software
4 affected components
gravitl netmaker<0.8.5
gravitl netmaker>=0.9.0<0.9.4
Netmaker netmaker<0.8.5
Netmaker netmaker>=0.9.0<0.9.4
Remediation
Event History
Feb 18, 2022
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-0664?
CVE-2022-0664 is considered a high severity vulnerability due to the use of hard-coded cryptographic keys.
2
How do I fix CVE-2022-0664?
To fix CVE-2022-0664, update to netmaker version 0.8.5 or later, or 0.9.4 and above.
3
Which versions of netmaker are affected by CVE-2022-0664?
CVE-2022-0664 affects netmaker versions prior to 0.8.5, as well as versions from 0.9.0 to 0.9.4.
4
What kind of vulnerability is CVE-2022-0664?
CVE-2022-0664 is classified as a cryptographic vulnerability due to the hard-coded keys used in the software.
5
What are the implications of CVE-2022-0664?
The implications of CVE-2022-0664 include potential unauthorized access and data exposure due to the predictability of hard-coded cryptographic keys.