CVE-2022-1592
Python vulnerability analysis and mitigation

Overview

Server-Side Request Forgery (SSRF) vulnerability was discovered in the scout repository by Clinical-Genomics prior to version 4.42. The vulnerability was identified in the remote_cors function in the alignviewers view component. This security issue was assigned CVE-2022-1592 and was discovered in May 2022 (GitHub Commit).

Technical details

The vulnerability exists in the remotecors function within the alignviewers view component. The issue allowed an attacker to make the application perform unauthorized requests. The fix involved implementing authentication checks and session track validation through the checksession_tracks function to ensure that users requesting resources are authenticated and the requested resources are present in the session IGV tracks (GitHub Commit).

Impact

The vulnerability could allow an attacker to perform unauthorized server-side requests through the application, potentially leading to unauthorized access to internal resources or data exposure.

Mitigation and workarounds

The issue was fixed in scout version 4.42 by implementing proper authentication checks and session validation. Users are advised to upgrade to this version or later. The fix includes the addition of the checksessiontracks function that verifies user authentication and validates that requested resources are present in session IGV tracks (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-65896CRITICAL9.8
  • PythonPython
  • asyncmy
NoNoDec 02, 2025
CVE-2025-66423HIGH7.1
  • PythonPython
  • tryton-server
NoYesNov 30, 2025
CVE-2025-66454MEDIUM6.5
  • PythonPython
  • arcade-mcp-server
NoYesDec 02, 2025
CVE-2025-66424MEDIUM6.5
  • PythonPython
  • trytond
NoYesNov 30, 2025
CVE-2025-65858LOW3.5
  • PythonPython
  • calibreweb
NoNoDec 02, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management