9.8

CVE-2022-34615

Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MealieMealie Version0.5.5
MealieMealie Version1.0.0 Updatebeta3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.11% 0.615
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-521 Weak Password Requirements

The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.

https://docs.mealie.io/changelog/v0.5.6/
Third Party Advisory
Release Notes
https://hub.docker.com/r/hkotel/mealie
Third Party Advisory
Product
https://cwe.mitre.org/data/definitions/521.html
Third Party Advisory
https://gainsec.com/2022/08/19/cve-2022-34615-cve-2022-34621-cve-2022-34623-cve-2022-34624/
Third Party Advisory