Record summary

CVE-2022-38817 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

github.com/dapr/dashboard

Browse Go / github.com/dapr/dashboard
GitHub Advisory0.1.0 to ≤ 0.10.0affected

Nuclei templates

1
ProjectDiscoveryHIGHDapr Dashboard 0.1.0-0.10.0 - Improper Access ControlCVSS 7.5

Dapr Dashboard 0.1.0 through 0.10.0 is susceptible to improper access control. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

The vulnerability allows unauthorized access to the Dapr Dashboard, potentially leading to unauthorized actions and data exposure.

Remediation

Upgrade Dapr Dashboard to a version that includes the fix for CVE-2022-38817 or apply the necessary patches provided by the vendor.

WeaknessesCWE-306
AuthorsFor3stCo1d
Template tagscvecve2022daprdashboardunauthlinuxfoundationvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:linuxfoundation:dapr_dashboard:*:*:*:*:*:*:*:*
Shodan: http.title:"Dapr Dashboard"
Shodan: http.title:"dapr dashboard"
FOFA: title="dapr dashboard"
Google: intitle:"dapr dashboard"

Source: ProjectDiscovery

References

3