Vulnerability CVE-2022-0664


Published: 2022-02-18

Description:
Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.

Type:

CWE-321

(Use of Hard-coded Cryptographic Key)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Gravitl -> Netmaker 

 References:
https://huntr.dev/bounties/29898a42-fd4f-4b5b-a8e3-ab573cb87eac
https://github.com/gravitl/netmaker/commit/9bee12642986cb9534e268447b70e6f0f03c59cf

Copyright 2024, cxsecurity.com

 

Back to Top