First published: Mon Nov 14 2022(Updated: )
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 does not issue a new session ID upon successful OAuth authentication. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Concretecms Concrete Cms | <8.5.10 | |
Concretecms Concrete Cms | >=9.0.0<=9.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43687 is medium with a CVSS score of 5.4.
CVE-2022-43687 affects Concrete CMS versions below 8.5.10 and between 9.0.0 and 9.1.2.
Remediate CVE-2022-43687 by updating Concrete CMS to version 9.1.3+ or 8.5.10+.
You can find more information about CVE-2022-43687 in the release notes of Concrete CMS versions 8.5.10 and 9.1.3, as well as on the official GitHub page of Concrete CMS.
The Common Weakness Enumeration (CWE) ID associated with CVE-2022-43687 is CWE-384.