CVE-2022-45183: High severity Ironmansoftware Powershell Universal vulnerability
Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Patched Versions are 3.5.3, 3.4.7, and 2.12.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ironman Software PowerShell Universalto a version that resolves this vulnerability.Fixed in 3.5.3 - Upgrade
Upgrade
Ironman Software PowerShell Universalto a version that resolves this vulnerability.Fixed in 3.4.7 - Upgrade
Upgrade
Ironman Software PowerShell Universalto a version that resolves this vulnerability.Fixed in 2.12.6
Event History
Frequently Asked Questions
What is CVE-2022-45183?
CVE-2022-45183 is a vulnerability in Ironman Software PowerShell Universal 2.x and 3.x that allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request.
What is the severity of CVE-2022-45183?
The severity of CVE-2022-45183 is high, with a severity value of 8.8.
How can I patch the vulnerability CVE-2022-45183?
To patch the vulnerability CVE-2022-45183, update your Ironman Software PowerShell Universal version to either 3.5.3, 3.4.7, or 2.12.6.
Where can I find more information about CVE-2022-45183?
You can find more information about CVE-2022-45183 on the Ironman Software blog at https://blog.ironmansoftware.com/psu-2022-11-cve/ and in the PowerShell Universal documentation at https://docs.powershelluniversal.com/changelog.
What is the CWE of CVE-2022-45183?
The CWE (Common Weakness Enumeration) of CVE-2022-45183 is 269.