CVE-2022-4861: Incorrect Implementation of Authentication Algorithm
Published Dec 30, 2022
·Updated
Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.
Affected Software
1 affected component
M-Files M-Files Client<22.5.11356.0
Remediation
Information
Upgrade to non-vulnerable version.
Event History
Dec 30, 2022
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-4861?
CVE-2022-4861 is a vulnerability in the authentication protocol implementation in M-Files Client before version 22.5.11356.0.
2
What is the severity of CVE-2022-4861?
The severity of CVE-2022-4861 is medium with a severity value of 4.9.
3
How does CVE-2022-4861 affect M-Files Client?
CVE-2022-4861 allows a high privileged user to get other users' tokens to another resource in M-Files Client before version 22.5.11356.0.
4
How can I fix CVE-2022-4861?
To fix CVE-2022-4861, update your M-Files Client to version 22.5.11356.0 or later.