CVE-2022-23610 is a critical vulnerability in wire-server, the backend for the Wire messenger, affecting versions prior to 2022-01-27. It allows attackers to bypass SAML SSO by crafting DSA signatures, enabling user impersonation and, in some cases, new account creation with fake SAML credentials. With a CVSS score of 8.1 (High), this vulnerability has a network attack vector, high attack complexity due to specific information requirements, and a severe impact on confidentiality, integrity, and availability. While there are no known active exploits, public exploit code, or significant community discussion, the vulnerability is patched in wire-server 2022-01-27, and on-premise instances require immediate updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.123.0CPE matchmatch criteria | cpe:2.3:a:wire:wire-server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.