CVE-2022-37033
dotCMS vulnerability analysis and mitigation

Overview

In dotCMS versions 5.x-22.06, a vulnerability was discovered in the TempFileAPI component that allows users to create temporary files based on passed URLs. The vulnerability, identified as CVE-2022-37033, was discovered by Fortinet's FortiGuard Labs in June 2022 and officially disclosed in August 2022. This security issue affects dotCMS installations from version 5.2.0 onwards (DotCMS Security, FortiGuard Labs).

Technical details

The vulnerability stems from the TempFileAPI's handling of URL redirects. While the system attempts to block SSRF (Server-Side Request Forgery) access to local IP addresses or private subnets, it follows 302 redirects from remote URLs without re-validating the redirect destination. This oversight allows attackers to bypass the initial security checks, as the system doesn't perform secondary validation on redirected URLs (DotCMS Security).

Impact

The vulnerability enables attackers to access and retrieve data from local/private hosts that should not be accessible remotely. This creates a potential security breach where internal network resources, such as elasticsearch instances running on port 9200, could be exposed to unauthorized access (DotCMS Security).

Mitigation and workarounds

DotCMS has released patches to address this vulnerability in versions 22.08+, LTS 21.06.12+, and LTS 22.03.4+. Organizations are strongly advised to upgrade to these versions. Additionally, as a workaround, administrators can implement a Web Application Firewall (WAF) to prevent POST requests to the /api/v1/temp/byUrl endpoint (DotCMS Security).

Additional resources


SourceThis report was generated using AI

Related dotCMS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-3938MEDIUM6.1
  • dotCMSdotCMS
  • cpe:2.3:a:dotcms:dotcms
NoYesJul 25, 2024
CVE-2023-3042MEDIUM6.1
  • dotCMSdotCMS
  • cpe:2.3:a:dotcms:dotcms
NoYesOct 17, 2023
CVE-2022-37034MEDIUM5.3
  • dotCMSdotCMS
  • cpe:2.3:a:dotcms:dotcms
NoYesFeb 01, 2023
CVE-2024-3165MEDIUM4.5
  • dotCMSdotCMS
  • cpe:2.3:a:dotcms:dotcms
NoYesApr 01, 2024
CVE-2024-3164MEDIUM4.5
  • dotCMSdotCMS
  • cpe:2.3:a:dotcms:dotcms
NoYesApr 01, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management