CVE-2022-37426: Malicious File Upload
Published Oct 28, 2022
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection.
Affected Software
4 affected components
OpenNebula OpenNebula<6.4.2
Linux Linux kernel
All of the following
OpenNebula OpenNebula<6.4.2
Linux Linux kernel
Remediation
Information
Upgrade to OpenNebula 6.4.2 EE LTS
Event History
Oct 28, 2022
CVE Published
03:09 PM
Data Sourced
03:09 PM
RemedyDescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2022-37426?
CVE-2022-37426 is considered a critical vulnerability due to the potential for file content injection.
2
How do I fix CVE-2022-37426?
To fix CVE-2022-37426, update OpenNebula to version 6.4.2 or a later release that addresses this vulnerability.
3
What systems are affected by CVE-2022-37426?
CVE-2022-37426 affects OpenNebula versions prior to 6.4.2 running on Linux.
4
What type of attack can CVE-2022-37426 facilitate?
CVE-2022-37426 facilitates file content injection attacks, which can lead to unauthorized code execution.
5
Is CVE-2022-37426 related to any other vulnerabilities?
CVE-2022-37426 is specific to OpenNebula and does not have direct relations to other listed vulnerabilities.