CVE-2022-3327

moderate-risk
Published 2022-10-20

Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

Do I need to act?

-
0.33% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: f2a32f2a9f3fb8be1a9432ac3d81d3aacdb13095, 323383d1db656f1b1291be529947bd943a6b0e99
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Vendors

47
/ 100
moderate-risk
Severity 32/34 · Critical
Exploitability 1/34 · Minimal
Exposure 14/34 · Moderate