CVE-2022-29354: Malicious File Upload
Published May 16, 2022
·Updated
An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file.
Affected Software
1 affected component
KeystoneJS Keystone Node.js=4.2.1
Event History
May 16, 2022
CVE Published
via MITRE·01:28 PM
Data Sourced
via MITRE·01:28 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-29354?
CVE-2022-29354 has a medium severity level due to its ability to allow arbitrary code execution through a file upload vulnerability.
2
How do I fix CVE-2022-29354?
To fix CVE-2022-29354, upgrade Keystone to version 4.2.2 or later where the vulnerability has been patched.
3
What type of attack is possible with CVE-2022-29354?
CVE-2022-29354 allows for arbitrary file upload attacks, enabling remote code execution on the server.
4
Which versions of Keystone are affected by CVE-2022-29354?
CVE-2022-29354 specifically affects Keystone version 4.2.1.
5
How can an attacker exploit CVE-2022-29354?
An attacker can exploit CVE-2022-29354 by uploading a specially crafted file that contains malicious code.