CVE-2022-24309: High severity mendix vulnerability

Published Mar 8, 2022
·
Updated

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29), Mendix Applications using Mendix 8 (All versions < V8.18.16), Mendix Applications using Mendix 9 (All deployments with Runtime Custom Setting DataStorage.UseNewQueryHandler set to False). If an entity has an association readable by the user, then in some cases, Mendix Runtime may not apply checks for XPath constraints that parse said associations, within apps running on affected versions. A malicious user could use this to dump and manipulate sensitive data.

Other sources

A vulnerability has been identified in Mendix Runtime V7 (All versions < V7.23.29), Mendix Runtime V8 (All versions < V8.18.16), Mendix Runtime V9 (All versions < V9.13 only with Runtime Custom Setting DataStorage.UseNewQueryHandler set to False). If an entity has an association readable by the user, then in some cases, Mendix Runtime may not apply checks for XPath constraints that parse said associations, within apps running on affected versions. A malicious user could use this to dump and manipulate sensitive data.

MITRE

Affected Software

4 affected components
Mendix Mendix<7.23.29
Mendix Mendix>=8.0.0<8.18.16
Mendix Mendix>=9.0.0
Mendix Mendix>=9.0.0<9.13

Event History

Mar 8, 2022
CVE Published
via MITRE·11:31 AM
Data Sourced
via MITRE·11:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the vulnerability ID of this vulnerability?

The vulnerability ID is CVE-2022-24309.

2

What is the severity level of CVE-2022-24309?

The severity level of CVE-2022-24309 is high.

3

Which software versions are affected by CVE-2022-24309?

Mendix Applications using Mendix 7 versions prior to V7.23.29, Mendix Applications using Mendix 8 versions prior to V8.18.16, and Mendix Applications using Mendix 9 versions from 9.0.0 onwards with the Runtime Custom Setting *DataStorage.UseNewQueryHandler* set to False are affected.

4

What is the Common Weakness Enumeration (CWE) ID associated with CVE-2022-24309?

The CWE ID associated with CVE-2022-24309 is CWE-284.

5

How can I fix CVE-2022-24309?

Update your Mendix application to version V7.23.29 or higher for Mendix 7, version V8.18.16 or higher for Mendix 8, or ensure that Mendix 9 deployments have the Runtime Custom Setting *DataStorage.UseNewQueryHandler* set to True.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203