CVE-2022-44544: Critical severity Mahara mahara vulnerability
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-44544?
CVE-2022-44544 is a vulnerability in Mahara before version 21.04.7, 21.10.5, 22.04.3, and 22.10.0 that potentially allows a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.
How can this vulnerability be exploited?
This vulnerability can be exploited by triggering a PDF export on a Mahara site running on Ubuntu where the flag -dSAFER is not set with Ghostscript.
What is the severity of CVE-2022-44544?
CVE-2022-44544 has a severity rating of 9.8 (Critical).
Which versions of Mahara are affected by CVE-2022-44544?
Mahara versions before 21.04.7, 21.10.5, 22.04.3, and 22.10.0 are affected by CVE-2022-44544.
How do I fix CVE-2022-44544?
To fix CVE-2022-44544, update Mahara to version 21.04.7, 21.10.5, 22.04.3, or 22.10.0.