First published: Mon Mar 06 2023(Updated: )
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.
Credit: security@m-files.com security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-files M-files Server | <22.11.12011.0 |
Upgrade to patched version of M-Files.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3284 is a vulnerability in M-Files New Web where the download key for a file in a vault was passed in an insecure way that could easily be logged.
The severity of CVE-2022-3284 is high, with a severity value of 7.5.
M-Files New Web versions before 22.11.12011.0 are affected by CVE-2022-3284.
To fix CVE-2022-3284, update M-Files New Web to version 22.11.12011.0 or later.
You can find more information about CVE-2022-3284 on the M-Files Trust Center security advisories page: [link](https://www.m-files.com/about/trust-center/security-advisories/cve-2022-3284/)