CVE-2022-34624: Medium severity Mealie Mealie vulnerability
Published Aug 19, 2022
·Updated
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.
Affected Software
2 affected components
Mealie Mealie=0.5.5
Mealie Mealie=1.0.0-beta3
Event History
Aug 19, 2022
CVE Published
via MITRE·01:22 PM
Data Sourced
via MITRE·01:22 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-34624?
CVE-2022-34624 has been classified as a high severity vulnerability due to its potential for exploitation through man-in-the-middle attacks.
2
How do I fix CVE-2022-34624?
To mitigate CVE-2022-34624, ensure that download tokens are properly terminated upon user logout.
3
Which versions of Mealie are affected by CVE-2022-34624?
CVE-2022-34624 affects Mealie version 1.0.0-beta3 and version 0.5.5.
4
What type of attack is possible due to CVE-2022-34624?
CVE-2022-34624 allows attackers to perform man-in-the-middle attacks by submitting crafted GET requests.
5
What can happen if CVE-2022-34624 is exploited?
If exploited, CVE-2022-34624 can lead to unauthorized access and data leakage during user sessions.