Vulnerabilities > CVE-2022-34621 - Authorization Bypass Through User-Controlled Key vulnerability in Mealie 0.5.5/1.0.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Common Weakness Enumeration (CWE)
References
- https://cwe.mitre.org/data/definitions/639.html
- https://cwe.mitre.org/data/definitions/639.html
- https://docs.mealie.io/changelog/v0.5.6/
- https://docs.mealie.io/changelog/v0.5.6/
- https://gainsec.com/2022/08/19/cve-2022-34615-cve-2022-34621-cve-2022-34623-cve-2022-34624/
- https://gainsec.com/2022/08/19/cve-2022-34615-cve-2022-34621-cve-2022-34623-cve-2022-34624/
- https://hub.docker.com/r/hkotel/mealie
- https://hub.docker.com/r/hkotel/mealie
- https://portswigger.net/web-security/access-control/idor
- https://portswigger.net/web-security/access-control/idor