Junglewise Threat Intelligence

CVE-2022-4719: PYSEC-2022-43005 - Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.

CVE-2022-4719 · Severity: low · CVSS 3 · Published 2022-12-27

Technologies: rdiffweb (PyPI). Vendors: PyPI.

Executive brief

rdiffweb is an open-source backup web interface for the rdiff-backup utility, used to manage and restore file backups remotely. The vulnerability involves business logic errors that could allow an authenticated user with high privileges to perform unauthorized actions or manipulate backup operations, though the exact impact is limited.

Technical details

The vulnerability is a business logic error in rdiffweb versions prior to 2.5.5. The attack requires administrative privileges and user interaction (CVSS v3 vector: AV:P/AC:L/PR:H/UI:R), meaning an authenticated high-privileged user must perform a specific action. The patch, released in version 2.5.5, addresses the logic flaw through a commit that adds notification functionality for SSH key changes. The vulnerability affects all versions from 0.x through 2.5.4.

Affected products

  • rdiffweb contributors rdiffweb before 2.5.5

Timeline

  • 2022-12-27: disclosed
  • 2022-12-27: patched: Fixed in version 2.5.5

References

Related threats