CVE-2022-0672: Infoleak
Published Feb 18, 2022
·Updated
A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive information locally if LemMinX is run under a privileged user.
Affected Software
1 affected component
Eclipse Lemminx<0.19.0
Event History
Feb 18, 2022
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2022-0672.
2
What is the severity of CVE-2022-0672?
The severity of CVE-2022-0672 is medium (CVSS score: 5.5).
3
What is affected by CVE-2022-0672?
LemMinX versions prior to 0.19.0 are affected by CVE-2022-0672.
4
How can unauthorized access be gained through the vulnerability?
Unauthorized access to sensitive information locally can be gained if LemMinX is run under a privileged user.
5
Is there a fix available for CVE-2022-0672?
Yes, upgrading to LemMinX version 0.19.0 or higher will fix the vulnerability.