CVE-2022-3284 – Insecure way of passing a download key
https://notcve.org/view.php?id=CVE-2022-3284
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0. • https://www.m-files.com/about/trust-center/security-advisories/cve-2022-3284 https://product.m-files.com/security-advisories/cve-2022-3284 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2022-4861 – Incorrect Implementation of Authentication Algorithm
https://notcve.org/view.php?id=CVE-2022-4861
Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource. La implementación incorrecta en el protocolo de autenticación en M-Files Client anterior a 22.5.11356.0 permite a usuarios con altos privilegios obtener tokens de otros usuarios para otro recurso. • https://www.m-files.com/about/trust-center/security-advisories/cve-2022-4861 https://product.m-files.com/security-advisories/cve-2022-4861 • CWE-287: Improper Authentication CWE-303: Incorrect Implementation of Authentication Algorithm •
CVE-2022-4858 – Insertion of Sensitive Information into Log File
https://notcve.org/view.php?id=CVE-2022-4858
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set. La inserción de información confidencial en archivos de registro en M-Files Server antes del 22.10.11846.0 podría permitir obtener tokens confidenciales de los registros, si se establecieran configuraciones específicas. • https://www.m-files.com/about/trust-center/security-advisories/cve-2022-4858 https://product.m-files.com/security-advisories/cve-2022-4858 • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2022-4264 – Incorrect privilege assignment in M-Files Web Server
https://notcve.org/view.php?id=CVE-2022-4264
Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration. La asignación de privilegios incorrecta en M-Files Web (Classic) en M-Files anterior a 22.8.11691.0 permite a usuarios con privilegios bajos cambiar alguna configuración. • https://www.m-files.com/about/trust-center/security-advisories/cve-2022-4264 https://product.m-files.com/security-advisories/cve-2022-4264 • CWE-269: Improper Privilege Management •
CVE-2022-4270 – Incorrect privilege assignment in M-Files Web Server
https://notcve.org/view.php?id=CVE-2022-4270
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally. Un problema de asignación de privilegios incorrectos en M-Files Web en versiones de M-Files Web anteriores a la 22.5.11436.1 podría haber cambiado los permisos accidentalmente. • https://www.m-files.com/about/trust-center/security-advisories/cve-2022-4270 https://product.m-files.com/security-advisories/cve-2022-4270 • CWE-269: Improper Privilege Management •