CVE Vulnerabilities

CVE-2022-48341

Published: Feb 23, 2023 | Modified: Mar 03, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Administrator can obtain System Administrator dashboard access by modifying the scope via the scopes parameter.

Affected Software

Name Vendor Start Version End Version
Thingsboard Thingsboard 3.4.1 (including) 3.4.1 (including)

References