5.8

CVE-2022-32550

An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue allowed a malicious server to convince a 1Password app or integration it is communicating with the 1Password service.

Data is provided by the National Vulnerability Database (NVD)
1password1password SwPlatformandroid Version >= 7.0 < 7.9.3
1password1password SwPlatformmacos Version >= 7.0 < 7.9.5
1password1password SwPlatformiphone_os Version >= 7.0 < 7.9.6
1password1password SwPlatformwindows Version >= 7.0 < 7.9.829
1password1password SwPlatformlinux Version >= 8.0 < 8.7.1
1password1password SwPlatformmacos Version >= 8.0 < 8.7.1
1password1password SwPlatformwindows Version >= 8.0 < 8.7.1
1password1password SwPlatformiphone_os Version >= 8.0 < 8.8.0-94
1password1password SwPlatformandroid Version >= 8.0 < 8.8.0-104
1password1password In The Browser Version < 2.3.4
1passwordCommand-line Version >= 2.0.0 < 2.3.0
1passwordCommand Line Interface Version >= 1.0.0 < 1.12.5
1passwordConnect Version < 1.5.3
1passwordScim Bridge Version < 2.3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.34% 0.556
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.8 2.2 2.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N