Beveiligingsadvies

CVE-2022-40274

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-09-30 16:18:57
Laatst bijgewerkt 2025-05-20 18:33:59
Toegewezen door Fluid Attacks
CVSS-score 7.8
Status PUBLISHED

Beschrijving

Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled.