CVE-2022-26314: Critical severity mendix vulnerability
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an unauthenticated remote attacker to efficiently brute force passwords in specific situations.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-26314?
CVE-2022-26314 is a vulnerability identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1) and Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2).
What is the severity of CVE-2022-26314?
The severity of CVE-2022-26314 is critical with a CVSS v3.1 score of 9.8.
How does CVE-2022-26314 affect the software?
CVE-2022-26314 affects the Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1) and Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2).
What is the CWE of CVE-2022-26314?
The CWE of CVE-2022-26314 is CWE-307 (Improper Restriction of Excessive Authentication Attempts).
Is there a fix available for CVE-2022-26314?
Yes, Mendix has released a fix for CVE-2022-26314. It is recommended to update to the latest version of the Mendix Forgot Password Appstore module.