CVE-2022-38187: Prevent access to sharing/rest/content/features/analyze to unauthorized users
Published Aug 15, 2022
·Updated
Prior to version 10.9.0, the sharing/rest/content/features/analyze endpoint is always accessible to anonymous users, which could allow an unauthenticated attacker to induce Esri Portal for ArcGIS to read arbitrary URLs.
Affected Software
1 affected component
Esri Portal for ArcGIS<10.9
Event History
Aug 15, 2022
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-38187?
CVE-2022-38187 is a vulnerability in Esri Portal for ArcGIS that allows an unauthenticated attacker to read arbitrary URLs.
2
How can an attacker exploit CVE-2022-38187?
An attacker can exploit CVE-2022-38187 by accessing the sharing/rest/content/features/analyze endpoint as an anonymous user.
3
What is the severity of CVE-2022-38187?
CVE-2022-38187 has a severity rating of high, with a CVSS score of 7.5.
4
Which version of Esri Portal for ArcGIS is affected by CVE-2022-38187?
Prior to version 10.9.0, Esri Portal for ArcGIS is affected by CVE-2022-38187.
5
How can I fix CVE-2022-38187?
To fix CVE-2022-38187, upgrade to version 10.9.0 or later of Esri Portal for ArcGIS.