CVE-2022-21829

CRITICAL

Concrete CMS <8.5.8 and 9.0.0-9.0.2 - Remote Code Execution via Insecure HTTP Zip Download

Title source: llm
STIX 2.1

Description

Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which could lead to an RCE. Fixed by enforcing ‘concrete_secure’ instead of ‘concrete’. Concrete now only makes requests over https even a request comes in via http. Concrete CMS security team ranked this 8 with CVSS v3.1 vector: AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Credit goes to Anna for reporting HackerOne 1482520.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0135
EPSS Percentile 67.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-319
Status published
Products (2)
concrete5/core 9.0.0 - 9.1.0Packagist
concretecms/concrete_cms < 8.5.8
Published Jun 24, 2022
Tracked Since Feb 18, 2026