5.9
CVSSv3

CVE-2022-34624

Published: 19/08/2022 Updated: 14/02/2024
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing malicious users to perform a man-in-the-middle attack via a crafted GET request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mealie mealie 0.5.5

mealie mealie 1.0.0