CVE-2022-43690: Medium severity ConcreteCMS Concrete Cms vulnerability
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacysalt so that limited authentication bypass could occur if using this functionality. Remediate by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Concrete CMSto a version that resolves this vulnerability.Fixed in 8.5.10+ - Upgrade
Upgrade
Concrete CMSto a version that resolves this vulnerability.Fixed in 9.1.3+
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-43690.
What is the severity of CVE-2022-43690?
The severity of CVE-2022-43690 is medium.
What is affected by CVE-2022-43690?
Concrete CMS (formerly concrete5) versions below 8.5.10 and between 9.0.0 and 9.1.2 are affected by CVE-2022-43690.
How can I fix CVE-2022-43690?
You can fix CVE-2022-43690 by updating to Concrete CMS 9.1.3+ or 8.5.10+.
Where can I find more information about CVE-2022-43690?
You can find more information about CVE-2022-43690 in the following references: [https://documentation.concretecms.org/developers/introduction/version-history/8510-release-notes](https://documentation.concretecms.org/developers/introduction/version-history/8510-release-notes) and [https://documentation.concretecms.org/developers/introduction/version-history/913-release-notes](https://documentation.concretecms.org/developers/introduction/version-history/913-release-notes).