First published: Wed Sep 28 2022(Updated: )
rdiffweb prior to version 2.4.9 is vulnerable to Use of Cache Containing Sensitive Information. Due to improper cache control, an attacker can view sensitive information even if they are not logged into an account. Version 2.4.9 contains a patch for this issue.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Ikus-soft Rdiffweb | <2.4.8 | |
pip/rdiffweb | <2.4.9 | 2.4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3292 is a vulnerability found in the GitHub repository ikus060/rdiffweb prior to version 2.4.8, which allows the use of cache containing sensitive information.
CVE-2022-3292 has a severity rating of medium with a CVSS score of 4.6.
The affected software by CVE-2022-3292 is Ikus-soft Rdiffweb prior to version 2.4.8.
To fix CVE-2022-3292, you should update the affected software to version 2.4.8 or later.
You can find more information about CVE-2022-3292 in the GitHub repository and the huntr.dev bounty page.