« Volver al listado

CVE-2022-28229

Estado: ModificadaAlta (7.5)—

La funcionalidad hash en userver anterior a 42059b6319661583b3080cab9b595d4f8ac48128 permite a los atacantes provocar una denegación de servicio a través de una solicitud HTTP manipulada, que implica colisiones.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-28229",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-28229",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-15T13:24:14.207155Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "browser-security@yandex-team.ru",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "userver",
          "versions": [
            {
              "status": "affected",
              "version": "All versions prior to version 42059b6319661583b3080cab9b595d4f8ac48128"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-12-23T22:15:08.710",
  "references": [
    {
      "url": "https://userver.tech/df/d3a/md_en_userver_security_changelog.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "browser-security@yandex-team.ru"
    },
    {
      "url": "https://userver.tech/df/d3a/md_en_userver_security_changelog.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted HTTP request, involving collisions."
    },
    {
      "lang": "es",
      "value": "La funcionalidad hash en userver anterior a 42059b6319661583b3080cab9b595d4f8ac48128 permite a los atacantes provocar una denegación de servicio a través de una solicitud HTTP manipulada, que implica colisiones."
    }
  ],
  "lastModified": "2026-06-17T04:38:11.660",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:userver:userver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E611467-F391-41F1-9FED-27D55D543A9F",
              "versionEndExcluding": "2022-11-18"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "browser-security@yandex-team.ru"
}