CVE-2022-4111: Improper Validation of Specified Quantity in Input in tooljet/tooljet
Published Nov 22, 2022
·Updated
Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures over 2MB.
Affected Software
1 affected component
Tooljet tooljet<1.27.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
tooljet/tooljetto a version that resolves this vulnerability.Fixed in 1.27
Event History
Nov 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-4111.
2
What is the severity of CVE-2022-4111?
The severity of CVE-2022-4111 is medium (6.5).
3
What is the impact of CVE-2022-4111?
CVE-2022-4111 can lead to a denial-of-service (DoS) attack by allowing a logged-in attacker to upload profile pictures over 2MB.
4
Which software versions are affected by CVE-2022-4111?
Versions of Tooljet Tooljet up to and excluding 1.27.0 are affected by CVE-2022-4111.
5
How can CVE-2022-4111 be fixed?
To fix CVE-2022-4111, update Tooljet Tooljet to version 1.27.0 or later.