CVE-2022-3327
moderate-risk
Published 2022-10-20
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
Do I need to act?
-
0.33% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: f2a32f2a9f3fb8be1a9432ac3d81d3aacdb13095, 323383d1db656f1b1291be529947bd943a6b0e99
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Vendors
References (5)
Permissions Required
https://huntr.dev/bounties/02207c8f-2b15-4a31-a86a-74fd2fca0ed1
Permissions Required
https://huntr.dev/bounties/02207c8f-2b15-4a31-a86a-74fd2fca0ed1
47
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
1/34 · Minimal
Exposure
14/34 · Moderate