CVE-2022-43687: Medium severity ConcreteCMS Concrete Cms vulnerability
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 does not issue a new session ID upon successful OAuth authentication. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Concrete CMS (formerly concrete5)to a version that resolves this vulnerability.Fixed in 9.1.3+ - Upgrade
Upgrade
Concrete CMS (formerly concrete5)to a version that resolves this vulnerability.Fixed in 8.5.10+
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43687?
The severity of CVE-2022-43687 is medium with a CVSS score of 5.4.
How does CVE-2022-43687 affect Concrete CMS?
CVE-2022-43687 affects Concrete CMS versions below 8.5.10 and between 9.0.0 and 9.1.2.
How can I fix CVE-2022-43687?
Remediate CVE-2022-43687 by updating Concrete CMS to version 9.1.3+ or 8.5.10+.
Where can I find more information about CVE-2022-43687?
You can find more information about CVE-2022-43687 in the release notes of Concrete CMS versions 8.5.10 and 9.1.3, as well as on the official GitHub page of Concrete CMS.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2022-43687?
The Common Weakness Enumeration (CWE) ID associated with CVE-2022-43687 is CWE-384.