CVE-2022-48341: High severity thingsboard advancedfeature vulnerability
ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-48341?
CVE-2022-48341 is a vulnerability in ThingsBoard 3.4.1 that could allow a remote authenticated attacker to achieve Vertical Privilege Escalation.
How severe is CVE-2022-48341?
CVE-2022-48341 has a severity rating of 8.8, which is considered high.
What is the affected software?
The affected software is ThingsBoard version 3.4.1.
How can a remote authenticated attacker exploit CVE-2022-48341?
A remote authenticated attacker can exploit CVE-2022-48341 by modifying the scope via the scopes parameter to obtain System Administrator dashboard access.
Is there any reference for CVE-2022-48341?
Yes, you can find more information about CVE-2022-48341 at the following references: [reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/238543) and [reference 2](https://thingsboard.io/docs/reference/releases/).