github.com
https://github.com/dapr/dashboard CVE-2022-38817
HIGHNuclei
Dapr Dashboard vulnerable to Incorrect Access Control
Record summary
CVE-2022-38817 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
github.com/dapr/dashboardBrowse Go / github.com/dapr/dashboard | GitHub Advisory | 0.1.0 to ≤ 0.10.0 | affected |
Nuclei templates
1ProjectDiscoveryHIGHDapr Dashboard 0.1.0-0.10.0 - Improper Access ControlCVSS 7.5
Dapr Dashboard 0.1.0 through 0.10.0 is susceptible to improper access control. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
The vulnerability allows unauthorized access to the Dapr Dashboard, potentially leading to unauthorized actions and data exposure.
Remediation
Upgrade Dapr Dashboard to a version that includes the fix for CVE-2022-38817 or apply the necessary patches provided by the vendor.
WeaknessesCWE-306
AuthorsFor3stCo1d
Template tagscvecve2022daprdashboardunauthlinuxfoundationvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:linuxfoundation:dapr_dashboard:*:*:*:*:*:*:*:*
Shodan: http.title:"Dapr Dashboard"
Shodan: http.title:"dapr dashboard"
FOFA: title="dapr dashboard"
Google: intitle:"dapr dashboard"
https://github.com/dapr/dashboard/issues/222 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38817 https://github.com/dapr/dashboard https://nvd.nist.gov/vuln/detail/CVE-2022-38817 https://github.com/Miraitowa70/POC-Notes
Source: ProjectDiscovery
References
3github.com
https://github.com/dapr/dashboard/issues/222 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-38817