CVE-2022-34625: Code Injection
Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to execute arbitrary code via a crafted Jinja2 template.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-34625?
CVE-2022-34625 is a Server-Side Template Injection vulnerability found in Mealie1.0.0beta3.
How does CVE-2022-34625 affect Mealie1.0.0beta3?
CVE-2022-34625 allows attackers to execute arbitrary code in Mealie1.0.0beta3 through a crafted Jinja2 template.
What is the severity of CVE-2022-34625?
CVE-2022-34625 has a severity rating of 7.2 (High).
How can I fix CVE-2022-34625?
To fix CVE-2022-34625, update Mealie to a version that is not affected by this vulnerability.
Where can I find more information about CVE-2022-34625?
You can find more information about CVE-2022-34625 in the Common Weakness Enumeration (CWE) at https://cwe.mitre.org/data/definitions/1336.html and https://cwe.mitre.org/data/definitions/94.html. You can also refer to the Mealie documentation at https://docs.mealie.io/changelog/v0.5.6/.