First published: Mon Dec 05 2022(Updated: )
Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to access K/V pairs of other users, potentially leading to the exposure of sensitive Information.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stackstorm Stackstorm | =3.7.0 | |
=3.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44009 is a vulnerability in StackStorm version 3.7.0 that allows attackers to access Key-Value (K/V) pairs of other users, potentially exposing sensitive information.
The severity of CVE-2022-44009 is high, with a severity value of 7.5.
CVE-2022-44009 affects StackStorm version 3.7.0 by exploiting improper access control in the Key-Value (K/V) RBAC, allowing unauthorized access to K/V pairs of other users.
Attackers can exploit CVE-2022-44009 by leveraging the lack of permission checks in Jinja filters to access K/V pairs of other users, potentially revealing sensitive information.
Yes, StackStorm has released version 3.8.0 which includes a fix for CVE-2022-44009. It is recommended to upgrade to the latest version to address the vulnerability.