CVE-2022-28995: Critical severity yogeshojha rengine vulnerability
Published May 20, 2022
·Updated
Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.
Affected Software
2 affected components
Yogeshojha Rengine=1.0.2
Rengine Project Rengine=1.0.2
Event History
May 20, 2022
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-28995?
CVE-2022-28995 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2022-28995?
To fix CVE-2022-28995, upgrade Rengine to version 1.0.3 or later where the vulnerability is addressed.
3
What type of vulnerability is CVE-2022-28995?
CVE-2022-28995 is classified as a remote code execution (RCE) vulnerability.
4
Are both Yogeshojha Rengine and Rengine Project Rengine affected by CVE-2022-28995?
Yes, both Yogeshojha Rengine and Rengine Project Rengine are affected by CVE-2022-28995 version 1.0.2.
5
What can an attacker achieve by exploiting CVE-2022-28995?
An attacker exploiting CVE-2022-28995 can execute arbitrary code on the server running the vulnerable version of Rengine.