CVE-2022-3348: Exposure of Sensitive Information to an Unauthorized Actor in tooljet/tooljet
Published Sep 28, 2022
·Updated
Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a little bit more specific, because it is needed to be an editor in the same app as the victim.
Affected Software
1 affected component
Tooljet tooljet<2022-09-11
Remediation
Event History
Sep 28, 2022
CVE Published
via MITRE·08:40 AM
Data Sourced
via MITRE·08:40 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3348?
CVE-2022-3348 is considered a high-severity vulnerability due to the potential for account theft by editors within the same application.
2
How do I fix CVE-2022-3348?
To fix CVE-2022-3348, update Tooljet to a version released after September 11, 2022, that addresses this vulnerability.
3
Who is affected by CVE-2022-3348?
Users who are editors within the same Tooljet application are specifically affected by CVE-2022-3348.
4
What kind of attack is associated with CVE-2022-3348?
CVE-2022-3348 is associated with an account theft attack, allowing one editor to steal accounts from other users.
5
What software versions are impacted by CVE-2022-3348?
CVE-2022-3348 impacts all versions of Tooljet prior to 2022-09-11.