CVE-2022-27978: High severity Tooljet tooljet vulnerability
Published Apr 26, 2023
·Updated
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.
Affected Software
1 affected component
Tooljet tooljet=1.6
Event History
Apr 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-27978?
CVE-2022-27978 is considered to be of high severity due to its potential for unauthorized password resets.
2
How do I fix CVE-2022-27978?
To fix CVE-2022-27978, update Tooljet to version 1.7 or later, which addresses the vulnerability.
3
What impact does CVE-2022-27978 have on Tooljet v1.6?
CVE-2022-27978 allows attackers to exploit missing value handling in the API to reset user passwords.
4
Is CVE-2022-27978 specific to certain versions of Tooljet?
Yes, CVE-2022-27978 specifically affects Tooljet version 1.6.
5
How can I determine if my system is vulnerable to CVE-2022-27978?
Check if your Tooljet deployment is running version 1.6, as it is vulnerable to CVE-2022-27978.