CVE-2022-29180: Charm vulnerable to server-side request forgery (SSRF)

Published May 7, 2022
·
Updated

A vulnerability in which attackers could forge HTTP requests to manipulate the charm data directory to access or delete anything on the server. This has been patched and is available in release v0.12.1. We recommend that all users running self-hosted charm instances update immediately. This vulnerability was found in-house and we haven't been notified of any potential exploiters. ### Additional notes Encrypted user data uploaded to the Charm server is safe as Charm servers cannot decrypt user data. This includes filenames, paths, and all key-value data. Users running the official Charm Docker images are at minimal risk because the exploit is limited to the containerized filesystem.

Affected Software

1 affected component
charm charm>=0.9.0<0.12.1

Event History

May 7, 2022
CVE Published
via MITRE·03:40 AM
Data Sourced
via MITRE·03:40 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is CVE-2022-29180?

CVE-2022-29180 is a vulnerability in which attackers could forge HTTP requests to manipulate the `charm` data directory to access or delete anything on the server.

2

How severe is CVE-2022-29180?

CVE-2022-29180 has a severity value of 9.8, which is considered critical.

3

Has CVE-2022-29180 been patched?

Yes, CVE-2022-29180 has been patched and the fix is available in release v0.12.1 of Charm.

4

Where can I find the patch for CVE-2022-29180?

The patch for CVE-2022-29180 can be found in release v0.12.1 of Charm, available at https://github.com/charmbracelet/charm/releases/tag/v0.12.1.

5

How can I protect myself from CVE-2022-29180?

To protect yourself from CVE-2022-29180, ensure that you update to version 0.12.1 or later of Charm.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203