CVE-2022-4879
Estado: ModificadaAlta (7.5)—
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to address this issue. The patch is named 6880971bd3d73d942384aff62d53058c206ce644. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217555.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.53%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-285
- NVD-CWE-Other
Referencias
- https://github.com/FAForever/fa/commit/6880971bd3d73d942384aff62d53058c206ce644
- https://github.com/FAForever/fa/pull/4398
- https://github.com/FAForever/fa/releases/tag/3747
- https://vuldb.com/?ctiid.217555
- https://vuldb.com/?id.217555
- https://github.com/FAForever/fa/commit/6880971bd3d73d942384aff62d53058c206ce644
- https://github.com/FAForever/fa/pull/4398
- https://github.com/FAForever/fa/releases/tag/3747
- https://vuldb.com/?ctiid.217555
- https://vuldb.com/?id.217555
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-4879",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-4879",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-28T13:35:55.970182Z"
}
}
],
"cvssMetricV2": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"version": "2.0",
"baseScore": 4.1,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:S/C:N/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 5.1,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.6,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 2.5,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cna@vuldb.com",
"affectedData": [
{
"vendor": "n/a",
"modules": [
"Vote Handler"
],
"product": "Forged Alliance Forever",
"versions": [
{
"status": "affected",
"version": "3746"
}
]
}
]
}
],
"published": "2023-01-06T11:15:09.557",
"references": [
{
"url": "https://github.com/FAForever/fa/commit/6880971bd3d73d942384aff62d53058c206ce644",
"tags": [
"Patch"
],
"source": "cna@vuldb.com"
},
{
"url": "https://github.com/FAForever/fa/pull/4398",
"tags": [
"Patch"
],
"source": "cna@vuldb.com"
},
{
"url": "https://github.com/FAForever/fa/releases/tag/3747",
"tags": [
"Release Notes"
],
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.217555",
"tags": [
"Permissions Required"
],
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.217555",
"tags": [
"Third Party Advisory"
],
"source": "cna@vuldb.com"
},
{
"url": "https://github.com/FAForever/fa/commit/6880971bd3d73d942384aff62d53058c206ce644",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/FAForever/fa/pull/4398",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/FAForever/fa/releases/tag/3747",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://vuldb.com/?ctiid.217555",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://vuldb.com/?id.217555",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@vuldb.com",
"description": [
{
"lang": "en",
"value": "CWE-285"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to address this issue. The patch is named 6880971bd3d73d942384aff62d53058c206ce644. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217555."
},
{
"lang": "es",
"value": "Una vulnerabilidad fue encontrada en Forged Alliance Forever hasta 3746. Ha sido declarada crítica. Una función desconocida del componente Vote Handler es afectada por esta vulnerabilidad. La manipulación conduce a una autorización inadecuada. La actualización a la versión 3747 puede solucionar este problema. El parche se llama 6880971bd3d73d942384aff62d53058c206ce644. Se recomienda actualizar el componente afectado. El identificador asociado de esta vulnerabilidad es VDB-217555."
}
],
"lastModified": "2026-06-17T05:22:05.870",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:forged_alliance_forever_project:forged_alliance_forever:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "08E0386C-FB01-49C5-9AC1-EE14CBC6F346",
"versionEndExcluding": "3747"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@vuldb.com"
}