CVE-2022-21829

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
24/06/2022
Last modified:
07/11/2023

Description

Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which could lead to an RCE. Fixed by enforcing ‘concrete_secure’ instead of ‘concrete’. Concrete now only makes requests over https even a request comes in via http. Concrete CMS security team ranked this 8 with CVSS v3.1 vector: AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Credit goes to Anna for reporting HackerOne 1482520.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* 8.5.8 (excluding)
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:* 9.0.0 (including) 9.1.0 (excluding)