« Volver al listado

CVE-2022-34914

Estado: ModificadaCrítica (9.8)—

Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {clientIp} variable can be used as an application startup argument. The X-Forwarded-For header can be manipulated by a client to store an arbitrary value that is used to replace the clientIp variable (without sanitization). A client can thus inject multiple arguments into the session startup. Systems that do not use the clientIP variable in the configuration are not vulnerable. The vulnerability is fixed in these versions: 20.1.16, 20.2.19, 21.1.8, 21.2.12, and 22.1.3.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-34914",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-07-08T19:15:08.640",
  "references": [
    {
      "url": "https://www.webswing.org/blog/header-injection-vulnerability-cve-2022-34914",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.webswing.org/docs/20.1/faq/client_ip.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.webswing.org/blog/header-injection-vulnerability-cve-2022-34914",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.webswing.org/docs/20.1/faq/client_ip.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-74"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {clientIp} variable can be used as an application startup argument. The X-Forwarded-For header can be manipulated by a client to store an arbitrary value that is used to replace the clientIp variable (without sanitization). A client can thus inject multiple arguments into the session startup. Systems that do not use the clientIP variable in the configuration are not vulnerable. The vulnerability is fixed in these versions: 20.1.16, 20.2.19, 21.1.8, 21.2.12, and 22.1.3."
    },
    {
      "lang": "es",
      "value": "Webswing versiones anteriores a 22.1.3, permite una inyección del encabezado X-Forwarded-For. La dirección IP del cliente está asociada a una variable en la página de configuración. La variable {clientIp} puede usarse como argumento de inicio de la aplicación. El encabezado X-Forwarded-For puede ser manipulado por un cliente para almacenar un valor arbitrario que es usado para reemplazar la variable clientIp (sin saneo). Un cliente puede así inyectar múltiples argumentos en el inicio de sesión. Los sistemas que no usan la variable clientIp en la configuración no son vulnerables. La vulnerabilidad está corregida en estas versiones: 20.1.16, 20.2.19, 21.1.8, 21.2.12 y 22.1.3"
    }
  ],
  "lastModified": "2026-06-17T04:51:08.897",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:webswing:webswing:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D96C9DDC-D82D-4E33-84EF-ACE64D113BB9",
              "versionEndExcluding": "20.1.16"
            },
            {
              "criteria": "cpe:2.3:a:webswing:webswing:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C0202EF-27EC-4178-A7C3-CD83C5C58481",
              "versionEndExcluding": "20.2.19",
              "versionStartIncluding": "20.2"
            },
            {
              "criteria": "cpe:2.3:a:webswing:webswing:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA3907BF-50D9-46A4-889D-A24C5678CA31",
              "versionEndExcluding": "21.1.8",
              "versionStartIncluding": "21.1.0"
            },
            {
              "criteria": "cpe:2.3:a:webswing:webswing:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6CF493A-235E-40C5-AAFA-EA0F22E9DB82",
              "versionEndExcluding": "21.2.12",
              "versionStartIncluding": "21.2.0"
            },
            {
              "criteria": "cpe:2.3:a:webswing:webswing:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5FDAC362-6CF2-40AA-95AC-E49A95A9C79C",
              "versionEndExcluding": "22.1.3",
              "versionStartIncluding": "22.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}