CVE-2022-31022 affects the Bleve text indexing library, specifically its HTTP utilities (bleve/http) used in sample applications and Couchbase Bleve. This vulnerability allows an attacker to create or delete directories on the filesystem where the Bleve index resides, provided the server user has write permissions. Rated Medium (CVSS 5.5), it requires local access (AV:L/PR:L) and has high impact on integrity (I:H), but is not actively exploited, lacks public exploit code, and has minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.0CPE matchmatch criteria | cpe:2.3:a:couchbase:bleve:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.