CVE-2022-0664
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
Use of Hard-coded Cryptographic Key in Netmaker in github.com/gravitl/netmaker
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@huntr.dev — https://huntr.dev/bounties/29898a42-fd4f-4b5b-a8e3-ab573cb87eac
Vendor advisory: security@huntr.dev — https://github.com/gravitl/netmaker/commit/9bee12642986cb9534e268447b70e6f0f03c59cf
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | github.com/gravitl/netmaker | <0.8.5 | 0.8.5 |
| Go | github.com/gravitl/netmaker | >=0.9.0,<0.9.4 | 0.9.4 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| netmaker | netmaker | {"endExcluding":"0.8.5"} | 0.8.5 |
References
CWEs
CWE-321
Verify integrity in audit chain (admin only). AS-IS.