CVE Database
/

CVE-2022-40238

Back to search

CVE-2022-40238

Published: Oct 26, 2022

Modified: May 7, 2025

PUBLISHED

Description

A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inject arbitrary pickle object as part of a user's profile. This can lead to code execution on the server when the user's profile is accessed.

VendorProductVersions

CERT/CC

VINCE - The Vulnerability Information and Coordination Environment

affected
1.48.0 - < 1.50.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now