CVE-2022-36110: Netmaker vulnerable to Insufficient Granularity of Access Control
Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API calls. If someone adds users to the Netmaker platform who do not have admin privileges, they can use their auth tokens to run admin-level functions via the API. This problem has been patched in v0.15.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36110?
CVE-2022-36110 has been rated as a high severity vulnerability due to its potential for unauthorized access to privileged API calls.
How do I fix CVE-2022-36110?
To fix CVE-2022-36110, update Netmaker to version 0.15.1 or later.
What types of systems are affected by CVE-2022-36110?
CVE-2022-36110 affects all versions of Netmaker prior to 0.15.1.
What is the impact of CVE-2022-36110 on users?
The impact of CVE-2022-36110 allows non-privileged users to execute admin-level API calls, compromising system security.
What is Netmaker and its relation to CVE-2022-36110?
Netmaker is a platform for creating networks with WireGuard, and CVE-2022-36110 highlights its improper authorization function vulnerability.