Incorrect Authorization in org.cometd.oort
CVE-2022-24721

8.1HIGH

Key Information:

Vendor

Cometd

Status
Vendor
CVE Published:
15 March 2022

What is CVE-2022-24721?

CometD is a scalable comet implementation for web messaging. In any version prior to 5.0.11, 6.0.6, and 7.0.6, internal usage of Oort and Seti channels is improperly authorized, so any remote user could subscribe and publish to those channels. By subscribing to those channels, a remote user may be able to watch cluster-internal traffic that contains other users' (possibly sensitive) data. By publishing to those channels, a remote user may be able to create/modify/delete other user's data and modify the cluster structure. A fix is available in versions 5.0.11, 6.0.6, and 7.0.6. As a workaround, install a custom SecurityPolicy that forbids subscription and publishing to remote, non-Oort, sessions on Oort and Seti channels.

Affected Version(s)

cometd < 5.0.11 < 5.0.11

cometd >= 6.0.0, < 6.0.6 < 6.0.0, 6.0.6

cometd >= 7.0.0, < 7.0.6 < 7.0.0, 7.0.6

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.