CVE-2022-32550

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/06/2022
Last modified:
25/03/2024

Description

An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue allowed a malicious server to convince a 1Password app or integration it is communicating with the 1Password service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:1password:1password:*:*:*:*:*:android:*:* 7.0 (including) 7.9.3 (excluding)
cpe:2.3:a:1password:1password:*:*:*:*:*:macos:*:* 7.0 (including) 7.9.5 (excluding)
cpe:2.3:a:1password:1password:*:*:*:*:*:iphone_os:*:* 7.0 (including) 7.9.6 (excluding)
cpe:2.3:a:1password:1password:*:*:*:*:*:windows:*:* 7.0 (including) 7.9.829 (excluding)
cpe:2.3:a:1password:1password:*:*:*:*:*:linux:*:* 8.0 (including) 8.7.1 (excluding)
cpe:2.3:a:1password:1password:*:*:*:*:*:macos:*:* 8.0 (including) 8.7.1 (excluding)
cpe:2.3:a:1password:1password:*:*:*:*:*:windows:*:* 8.0 (including) 8.7.1 (excluding)
cpe:2.3:a:1password:1password:*:*:*:*:*:iphone_os:*:* 8.0 (including) 8.8.0-94 (excluding)
cpe:2.3:a:1password:1password:*:*:*:*:*:android:*:* 8.0 (including) 8.8.0-104 (excluding)
cpe:2.3:a:1password:1password_in_the_browser:*:*:*:*:*:*:*:* 2.3.4 (excluding)
cpe:2.3:a:1password:command-line:*:*:*:*:*:*:*:* 2.0.0 (including) 2.3.0 (excluding)
cpe:2.3:a:1password:command_line_interface:*:*:*:*:*:*:*:* 1.0.0 (including) 1.12.5 (excluding)
cpe:2.3:a:1password:connect:*:*:*:*:*:*:*:* 1.5.3 (excluding)
cpe:2.3:a:1password:scim_bridge:*:*:*:*:*:*:*:* 2.3.2 (excluding)


References to Advisories, Solutions, and Tools