CVE-2022-41217

CRITICAL

Cloudflow - Unauthenticated File Upload

Title source: llm
STIX 2.1

Description

Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://csirt.divd.nl/CVE-2022-41217
Various Sources related
https://csirt.divd.nl/DIVD-2022-00052

Scores

CVSS v3 9.8
EPSS 0.0067
EPSS Percentile 71.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
hybridsoftware/cloudflow 2.0.0 - 2.3.2
Published Feb 22, 2023
Tracked Since Feb 18, 2026