CVE-2022-34112: Medium severity dataease project vulnerability
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34112?
CVE-2022-34112 is classified as a medium severity vulnerability due to its potential impact on system integrity.
How do I fix CVE-2022-34112?
To fix CVE-2022-34112, update Dataease to version 1.12.0 or later where the access control issue has been resolved.
What impact does CVE-2022-34112 have on my system?
CVE-2022-34112 allows unauthorized users to uninstall plugins, potentially disrupting services and compromising system integrity.
Is CVE-2022-34112 being actively exploited?
As of now, there is no public information indicating that CVE-2022-34112 is being actively exploited in the wild.
Who is affected by CVE-2022-34112?
CVE-2022-34112 affects users of Dataease version 1.11.1 who have not applied the necessary security updates.