CVE-2022-2901: Improper Authorization in chatwoot/chatwoot
Published Sep 6, 2022
·Updated
Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
Affected Software
1 affected component
chatwoot Chatwoot<2.8.0
Remediation
Event History
Sep 6, 2022
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2022-2901.
2
What is the severity level of CVE-2022-2901?
CVE-2022-2901 has a severity level of high (7.1).
3
What software versions are affected by CVE-2022-2901?
CVE-2022-2901 affects versions up to and exclusive of 2.8.0 of Chatwoot Chatwoot.
4
How can I fix CVE-2022-2901?
To fix CVE-2022-2901, update your Chatwoot Chatwoot installation to version 2.8.0 or higher.
5
Where can I find more information about CVE-2022-2901?
You can find more information about CVE-2022-2901 at the following references: [GitHub commit](https://github.com/chatwoot/chatwoot/commit/329e8c37c8ebc1b3629c0c3830b0e3070a3adc2a) and [Huntr Security](https://huntr.dev/bounties/cf46e0a6-f1b5-4959-a952-be9e4bac03fe).