CVE-2022-3167
HIGH8.8EPSS 0.40%rdiffweb vulnerable to Improper Restriction of Rendered UI Layers or Frames
發布日:2022/9/9修改日:2024/10/25
描述
rdiffweb prior to 2.4.1 is vulnerable to Improper Restriction of Rendered UI Layers or Frames. This allows attackers to perform clickjacking attacks that can trick victims into performing actions such as entering passwords, liking or deleting posts, and/or initiating an account deletion. This issue has been patched in version 2.4.1.
受影響套件(2)
- PyPI/rdiffwebfrom 0, < 2.4.1
- PyPI/rdiffwebfrom 0, < 7294bb7466532762c93d711211e5958940c1b428 | from 0, < 2.4.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
參考連結(6)
- ADVISORYhttps://github.com/advisories/GHSA-m379-x4xc-38x9
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-3167
- PATCHhttps://github.com/ikus060/rdiffweb
- WEBhttps://github.com/ikus060/rdiffweb/commit/7294bb7466532762c93d711211e5958940c1b428
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-268.yaml
- WEBhttps://huntr.dev/bounties/e5c2625b-34cc-4805-8223-80f2689e4e5c