CVE-2022-39222 is a medium-severity vulnerability affecting Dex, an OpenID Connect identity service, specifically instances with public clients running versions prior to 2.35.0. An attacker can exploit this by tricking a victim into navigating to a malicious website, stealing the OAuth authorization code, and then exchanging it for a token to gain unauthorized access to applications. The CVSS score is 6.5 (MEDIUM) with a vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N, indicating a network-based attack with low complexity, requiring user interaction, and leading to high confidentiality impact. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion with 10 mentions, surpassing 99% of all CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.35.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:dex:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.