CVE-2022-23553

HIGH

Alpine < 1.10.4 - Incorrect Authorization

Title source: rule
STIX 2.1

Description

Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds.

Scores

CVSS v3 7.5
EPSS 0.0028
EPSS Percentile 51.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
alpine_project/alpine < 1.10.4
us.springett/alpine 0 - 1.10.4Maven
Published Dec 28, 2022
Tracked Since Feb 18, 2026