CVE-2022-26847: Infoleak
Published Mar 10, 2022
·Updated
SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.
Affected Software
5 affected components
Spip SPIP<3.2.14
Spip SPIP>=4.0.0<4.0.5
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Event History
Mar 10, 2022
CVE Published
via MITRE·04:58 AM
Data Sourced
via MITRE·04:58 AM
Description
Frequently Asked Questions
1
What is CVE-2022-26847?
CVE-2022-26847 is a vulnerability in SPIP before 3.2.14 and 4.x before 4.0.5 that allows unauthenticated access to information about editorial objects.
2
What is the severity of CVE-2022-26847?
CVE-2022-26847 has a severity score of 5.3, which is considered medium.
3
How can unauthenticated access to information about editorial objects be exploited?
Unauthenticated attackers can exploit CVE-2022-26847 to gain access to information about editorial objects within SPIP.
4
Which versions of SPIP are affected by CVE-2022-26847?
SPIP versions before 3.2.14 and 4.x before 4.0.5 are affected by CVE-2022-26847.
5
How can I fix CVE-2022-26847?
To fix CVE-2022-26847, update to SPIP version 3.2.14 or install SPIP version 4.0.5 or later.