
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-4724 is a security vulnerability identified in GitHub repository ikus060/rdiffweb versions prior to 2.5.5. The vulnerability is classified as an Improper Access Control issue (Debian Security).
The vulnerability relates to SSH key management in rdiffweb. The issue allowed SSH keys to be duplicated across different users, which could potentially lead to unauthorized access. The fix implemented ensures that all SSH keys are unique regardless of the user by creating a unique index on the SSH key fingerprint (GitHub Commit).
The vulnerability could allow multiple users to share the same SSH key, potentially leading to unauthorized access to user accounts and their associated backup data (GitHub Commit).
The issue has been fixed in rdiffweb version 2.5.5. Users should upgrade to this version or later to address the vulnerability. The fix includes implementation of unique constraints on SSH key fingerprints to prevent duplicate keys across different users (GitHub Commit).
The vulnerability was discovered and reported by Nehal Pillai, who was credited in the project's documentation for identifying the SSH key uniqueness issue (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."