CVE-2022-39281

Source
https://cve.org/CVERecord?id=CVE-2022-39281
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39281.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-39281
Aliases
Published
2022-10-08T00:00:00Z
Modified
2026-04-10T04:50:20.320323Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Remote Denial of Service via Tasks endpoint in fat_free_crm
Details

fatfreecrm is a an open source, Ruby on Rails customer relationship management platform (CRM). In versions prior to 0.20.1 an authenticated user can perform a remote Denial of Service attack against Fat Free CRM via bucket access. The vulnerability has been patched in commit c85a254 and will be available in release 0.20.1. Users are advised to upgrade or to manually apply patch c85a254. There are no known workarounds for this issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39281.json"
}
References

Affected packages

Git / github.com/fatfreecrm/fat_free_crm

Affected ranges

Type
GIT
Repo
https://github.com/fatfreecrm/fat_free_crm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*
0.10.1
0.10.1-rc3
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
0.9.8
0.9.9
0.9.9a
v0.*
v0.11.2
v0.11.3
v0.11.4
v0.12.0
v0.13.0
v0.13.1
v0.13.2
v0.13.3
v0.13.4
v0.13.5
v0.13.6
v0.15.0
v0.15.0-beta.2
v0.16.0
v0.17.0
v0.18.0
v0.19.1
v0.20.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39281.json"