CVE Vulnerabilities

CVE-2022-45292

Operation on a Resource after Expiration or Release

Published: Dec 09, 2022 | Modified: Dec 13, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

User invites for Funkwhale v1.2.8 do not permanently expire after being used for signup and can be used again after an account has been deleted.

Weakness

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

Affected Software

Name Vendor Start Version End Version
Funkwhale Funkwhale 1.2.8 (including) 1.2.8 (including)

References