CVE-2022-2111: Unrestricted Upload of File with Dangerous Type in inventree/inventree
Published Jun 17, 2022
·Updated
Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.
Affected Software
1 affected component
Inventree Project Inventree<0.7.2
Remediation
Event History
Jun 17, 2022
CVE Published
via MITRE·10:10 AM
Data Sourced
via MITRE·10:10 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2111?
CVE-2022-2111 has been assigned a medium severity rating due to the potential for attackers to upload dangerous files.
2
How do I fix CVE-2022-2111?
To fix CVE-2022-2111, update your Inventree installation to version 0.7.2 or later, which addresses this vulnerability.
3
Which versions of Inventree are affected by CVE-2022-2111?
CVE-2022-2111 affects all versions of Inventree prior to 0.7.2.
4
What kind of files are vulnerable due to CVE-2022-2111?
CVE-2022-2111 allows the unrestricted upload of files with dangerous types, which can pose security risks.
5
Can CVE-2022-2111 lead to remote code execution?
While CVE-2022-2111 primarily involves file uploads, it could potentially lead to remote code execution if the uploaded files are executed by the server.