CVE-2022-43686: Medium severity ConcreteCMS Concrete Cms vulnerability
In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can be filled up causing a denial of service (high load).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/concrete5/concrete5to a version that resolves this vulnerability.Fixed in 9.1.3 - Upgrade
Upgrade
composer/concrete5/concrete5to a version that resolves this vulnerability.Fixed in 8.5.10
Event History
Frequently Asked Questions
What is CVE-2022-43686?
CVE-2022-43686 is a vulnerability in Concrete CMS that can cause a denial of service due to high load.
What versions of Concrete CMS are affected by CVE-2022-43686?
Concrete CMS versions below 8.5.10 and between 9.0.0 and 9.1.2 are affected by CVE-2022-43686.
How can CVE-2022-43686 be exploited?
CVE-2022-43686 can be exploited by filling up the authTypeConcreteCookieMap table, which causes a denial of service due to high load.
What is the severity of CVE-2022-43686?
CVE-2022-43686 has a severity rating of 6.5, classified as medium.
How can I fix CVE-2022-43686?
To fix CVE-2022-43686, upgrade to Concrete CMS version 9.1.3 or apply the fix provided in the official documentation.