First published: Tue Dec 13 2022(Updated: )
Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Campaign | <7.3.2 | |
Adobe Campaign | >=8.0.0<8.4.2 | |
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42343 is a Server-Side Request Forgery (SSRF) vulnerability in Adobe Campaign version 7.3.1 and earlier, and 8.3.9 and earlier, which could lead to arbitrary file system read.
The vulnerability allows a low-privilege authenticated attacker to force the application to make arbitrary requests, potentially resulting in arbitrary file system read.
The severity of CVE-2022-42343 is medium with a CVSS score of 6.5.
Adobe has released security updates to address this vulnerability, it is recommended to update to the latest version of Adobe Campaign.
You can find more information about CVE-2022-42343 on the Adobe Security Bulletin APSB22-58.