CVE-2022-31122 is a high-severity Token Recipient Confusion vulnerability affecting Wire encrypted communication and collaboration platform versions prior to 2022-07-12/Chart 4.19.0. An attacker with specific SAML IdP metadata can delete SAML-authenticated accounts, authenticate as a user, and create arbitrary accounts within a targeted team if not managed by SCIM. The vulnerability has a CVSS score of 8.1 (High) due to its network attack vector, high impact on confidentiality, integrity, and availability, and high attack complexity. While the issue is fixed in wire-server 2022-07-12 and deployed on Wire managed services, on-premise instances require an update or disabling SAML configuration as a workaround. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2022-07-12CPE matchmatch criteria | cpe:2.3:a:wire:wire_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.