CVE-2022-24901
Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter
7.5
HIGH
CVSS 3.1
EPSS 0.64%
描述
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it.
如何修補 CVE-2022-24901
要修補 CVE-2022-24901,請將受影響套件升級到下列已修補版本。
- —升級至 4.10.10 或更新版本
- —升級至 4.10.10 或更新版本
CVE-2022-24901 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 4.10.10, >= 5.0.0, < 5.2.1
- from 0, < 4.10.10
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |