CVE-2022-34623: Medium severity mealie vulnerability

Published Aug 19, 2022
·
Updated

Mealie1.0.0beta3 is vulnerable to user enumeration via timing response discrepancy between users and non-users when an invalid password message is displayed during an authentication attempt.

Other sources

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-32425. Reason: This candidate is a duplicate of CVE-2022-32425. Notes: All CVE users should reference CVE-2022-32425 instead of this candidate.

NVD

Affected Software

2 affected components
Mealie Mealie=0.5.5
Mealie Mealie=1.0.0-beta3

Event History

Jan 1, 1970
CVE Published
via MITRE·12:00 AM
Aug 19, 2022
CVE Published
02:15 PM
Data Sourced
via NVD·02:15 PM
Description
May 7, 2024
Rejected
via MITRE·05:52 PM
Rejected
via MITRE·05:58 PM

Frequently Asked Questions

1

What is the severity of CVE-2022-34623?

CVE-2022-34623 has a medium severity rating due to its potential for user enumeration.

2

How do I fix CVE-2022-34623?

To fix CVE-2022-34623, it is recommended to upgrade to Mealie version 0.5.6 or later.

3

What software is affected by CVE-2022-34623?

CVE-2022-34623 affects Mealie versions 0.5.5 and 1.0.0-beta3.

4

What kind of attack does CVE-2022-34623 enable?

CVE-2022-34623 allows for user enumeration through timing discrepancies in authentication responses.

5

Is CVE-2022-34623 being addressed in updates?

Yes, CVE-2022-34623 has been addressed in subsequent software updates to enhance security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203