CVE Vulnerabilities

CVE-2022-23067

Published: May 18, 2022 | Modified: May 26, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer header. Using these tokens the attacker can access the user’s account.

Affected Software

Name Vendor Start Version End Version
Tooljet Tooljet 0.5.0 (including) 1.2.2 (including)

References