CVE-2022-3284: Insecure way of passing a download key
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-3284?
CVE-2022-3284 is a vulnerability in M-Files New Web where the download key for a file in a vault was passed in an insecure way that could easily be logged.
What is the severity of CVE-2022-3284?
The severity of CVE-2022-3284 is high, with a severity value of 7.5.
Which software is affected by CVE-2022-3284?
M-Files New Web versions before 22.11.12011.0 are affected by CVE-2022-3284.
How can I fix CVE-2022-3284?
To fix CVE-2022-3284, update M-Files New Web to version 22.11.12011.0 or later.
Where can I find more information about CVE-2022-3284?
You can find more information about CVE-2022-3284 on the M-Files Trust Center security advisories page: [link](https://www.m-files.com/about/trust-center/security-advisories/cve-2022-3284/)