CVE-2022-45003: High severity gophish vulnerability
Published Mar 22, 2023
·Updated
Gophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.
Affected Software
2 affected components
Getgophish Gophish<=0.12.1
go/github.com/gophish/gophish<=0.12.1
Event History
Mar 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·09:30 PM
Data Sourced
via GitHub·09:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45003?
CVE-2022-45003 is classified as a Denial of Service (DoS) vulnerability.
2
What impact does CVE-2022-45003 have on Gophish users?
CVE-2022-45003 allows attackers to exploit a crafted payload leading to application unavailability.
3
How do I fix CVE-2022-45003?
To mitigate CVE-2022-45003, update Gophish to version 0.12.2 or later.
4
Which versions of Gophish are affected by CVE-2022-45003?
CVE-2022-45003 affects Gophish versions up to and including 0.12.1.
5
Is there a workaround for CVE-2022-45003 while I can't update?
There is no documented workaround for CVE-2022-45003, so updating is the recommended approach.