CVE-2022-23067: ToolJet - Token Leakage via Referer Header
Published May 18, 2022
·Updated
ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer header. Using these tokens the attacker can access the user’s account.
Affected Software
1 affected component
Tooljet tooljet>=0.5.0<=1.2.2
Remediation
Information
Update to version v1.3.0 or later
Event History
May 18, 2022
CVE Published
via MITRE·11:45 AM
Data Sourced
via MITRE·11:45 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-23067.
2
What is the severity of CVE-2022-23067?
The severity of CVE-2022-23067 is high with a value of 8.8.
3
Which versions of ToolJet are affected by CVE-2022-23067?
ToolJet versions v0.5.0 to v1.2.2 are affected by CVE-2022-23067.
4
How does CVE-2022-23067 work?
CVE-2022-23067 allows for token leakage via the Referer header, which can lead to account takeover.
5
How can I fix CVE-2022-23067?
Updating ToolJet to a version higher than v1.2.2 will fix the vulnerability.