CVE-2022-34466: Medium severity mendix vulnerability
A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.3). An expression injection vulnerability was discovered in the Workflow subsystem of Mendix Runtime, that can affect the running applications. The vulnerability could allow a malicious user to leak sensitive information in a certain configuration.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-34466?
CVE-2022-34466 is a vulnerability identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15) and Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.3).
What is the severity of CVE-2022-34466?
The severity of CVE-2022-34466 is medium.
What is the affected software by CVE-2022-34466?
The affected software by CVE-2022-34466 is Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15) and Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.3).
What is the CWE of CVE-2022-34466?
The CWE of CVE-2022-34466 is CWE-917 and CWE-74.
How can I fix CVE-2022-34466?
To fix CVE-2022-34466, it is recommended to update the affected Mendix Applications to versions V9.12.3 or V9.15.0 depending on the specific version.