CVE-2022-34623: Medium severity mealie vulnerability
Mealie1.0.0beta3 is vulnerable to user enumeration via timing response discrepancy between users and non-users when an invalid password message is displayed during an authentication attempt.
Other sources
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-32425. Reason: This candidate is a duplicate of CVE-2022-32425. Notes: All CVE users should reference CVE-2022-32425 instead of this candidate.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34623?
CVE-2022-34623 has a medium severity rating due to its potential for user enumeration.
How do I fix CVE-2022-34623?
To fix CVE-2022-34623, it is recommended to upgrade to Mealie version 0.5.6 or later.
What software is affected by CVE-2022-34623?
CVE-2022-34623 affects Mealie versions 0.5.5 and 1.0.0-beta3.
What kind of attack does CVE-2022-34623 enable?
CVE-2022-34623 allows for user enumeration through timing discrepancies in authentication responses.
Is CVE-2022-34623 being addressed in updates?
Yes, CVE-2022-34623 has been addressed in subsequent software updates to enhance security.