{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2022-41708","assignerOrgId":"84fe0718-d6bb-4716-a7e8-81a6d1daa869","assignerShortName":"Fluid Attacks","dateUpdated":"2025-05-08T20:06:09.780Z","dateReserved":"2022-09-28T00:00:00.000Z","datePublished":"2022-10-19T00:00:00.000Z"},"containers":{"cna":{"providerMetadata":{"orgId":"84fe0718-d6bb-4716-a7e8-81a6d1daa869","shortName":"Fluid Attacks","dateUpdated":"2022-10-19T00:00:00.000Z"},"descriptions":[{"lang":"en","value":"Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible because the application does not validate permissions correctly."}],"affected":[{"vendor":"n/a","product":"relatedcode/Messenger","versions":[{"version":"7bcd20b","status":"affected"}]}],"references":[{"url":"https://github.com/relatedcode/Messenger"},{"url":"https://fluidattacks.com/advisories/tiesto/"}],"problemTypes":[{"descriptions":[{"type":"text","lang":"en","description":"Improper authorization control for web services"}]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T12:49:44.045Z"},"title":"CVE Program Container","references":[{"url":"https://github.com/relatedcode/Messenger","tags":["x_transferred"]},{"url":"https://fluidattacks.com/advisories/tiesto/","tags":["x_transferred"]}]},{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-281","lang":"en","description":"CWE-281 Improper Preservation of Permissions"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":4.3,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"LOW","confidentialityImpact":"LOW"}},{"other":{"type":"ssvc","content":{"timestamp":"2025-05-08T20:06:04.751501Z","id":"CVE-2022-41708","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-05-08T20:06:09.780Z"}}]}}