CVE-2023-22495 is a critical authentication bypass vulnerability affecting Izanami, a shared configuration service, specifically when deployed via its official Docker image. The flaw stems from a hardcoded secret used to sign JSON Web Tokens (JWTs), allowing an unauthenticated attacker to compromise Izanami instances. With a CVSS score of 9.8 (Critical), this vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, the issue has been patched in Izanami version 1.11.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.11.0CPE matchmatch criteria | cpe:2.3:a:maif:izanami:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.