CVE-2022-45292

User invites for Funkwhale v1.2.8 do not permanently expire after being used for signup and can be used again after an account has been deleted.
References
Link Resource
https://dev.funkwhale.audio/funkwhale/funkwhale/-/issues/1952 Exploit Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:funkwhale:funkwhale:1.2.8:*:*:*:*:*:*:*

History

13 Dec 2022, 00:36

Type Values Removed Values Added
CPE cpe:2.3:a:funkwhale:funkwhale:1.2.8:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References (MISC) https://dev.funkwhale.audio/funkwhale/funkwhale/-/issues/1952 - (MISC) https://dev.funkwhale.audio/funkwhale/funkwhale/-/issues/1952 - Exploit, Issue Tracking, Vendor Advisory
First Time Funkwhale
Funkwhale funkwhale
CWE CWE-672

09 Dec 2022, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-09 22:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-45292

Mitre link : CVE-2022-45292

CVE.ORG link : CVE-2022-45292


JSON object : View

Products Affected

funkwhale

  • funkwhale
CWE
CWE-672

Operation on a Resource after Expiration or Release