CVE-2022-31149
Estado: ModificadaCrítica (9.6)—
ActivityWatch open-source automated time tracker. Versions prior to 0.12.0b2 are vulnerable to DNS rebinding attacks. This vulnerability impacts everyone running ActivityWatch and gives the attacker full access to the ActivityWatch REST API. Users should upgrade to v0.12.0b2 or later to receive a patch. As a workaround, block DNS lookups that resolve to 127.0.0.1.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Puntuación base: 9.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.26%
- Percentil entre todas las CVEs puntuadas: 69
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-290
Referencias
- https://gist.github.com/zozs/fdebbce75fc8538c15851b46db944a16
- https://github.com/ActivityWatch/activitywatch/discussions/778
- https://github.com/ActivityWatch/activitywatch/security/advisories/GHSA-v9fg-6g9j-h4x4
- https://gist.github.com/zozs/fdebbce75fc8538c15851b46db944a16
- https://github.com/ActivityWatch/activitywatch/discussions/778
- https://github.com/ActivityWatch/activitywatch/security/advisories/GHSA-v9fg-6g9j-h4x4
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-31149",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-31149",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-04-22T15:42:23.200692Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.6,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "ActivityWatch",
"product": "activitywatch",
"versions": [
{
"status": "affected",
"version": "< 0.12.0b2"
}
]
}
]
}
],
"published": "2022-09-07T14:15:08.760",
"references": [
{
"url": "https://gist.github.com/zozs/fdebbce75fc8538c15851b46db944a16",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/ActivityWatch/activitywatch/discussions/778",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/ActivityWatch/activitywatch/security/advisories/GHSA-v9fg-6g9j-h4x4",
"tags": [
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://gist.github.com/zozs/fdebbce75fc8538c15851b46db944a16",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/ActivityWatch/activitywatch/discussions/778",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/ActivityWatch/activitywatch/security/advisories/GHSA-v9fg-6g9j-h4x4",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-290"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "ActivityWatch open-source automated time tracker. Versions prior to 0.12.0b2 are vulnerable to DNS rebinding attacks. This vulnerability impacts everyone running ActivityWatch and gives the attacker full access to the ActivityWatch REST API. Users should upgrade to v0.12.0b2 or later to receive a patch. As a workaround, block DNS lookups that resolve to 127.0.0.1."
},
{
"lang": "es",
"value": "ActivityWatch es un sistema automatizado de seguimiento del tiempo de código abierto. Las versiones anteriores a 0.12.0b2 son vulnerables a ataques de reenganche de DNS. Esta vulnerabilidad afecta a todos los que ejecutan ActivityWatch y da al atacante acceso completo a la API REST de ActivityWatch. Los usuarios deben actualizar a versión 0.12.0b2 o posteriores para recibir un parche. Como mitigación, bloquee las búsquedas de DNS que resuelven a 127.0.0.1"
}
],
"lastModified": "2026-06-17T04:44:54.407",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:activitywatch:activitywatch:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "32D5260B-3B92-4642-8464-0F49DB8A9A5C",
"versionEndExcluding": "0.12.0"
},
{
"criteria": "cpe:2.3:a:activitywatch:activitywatch:0.12.0:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8D7869F0-4EC4-4ADC-BF24-596ED4124D21"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}