CVE-2022-45929: Northern.tech Mender
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could allow privilege escalation from a low-privileged read-only user to a high-privileged user.
Affected products
- Northern.tech Mender: from 3.3, before 3.3.2 (fixed in 3.3.2); from 3.5, before 3.5.0 (fixed in 3.5.0); from 3.6, before 3.6.0 (fixed in 3.6.0)
Published 2024-06-20. Last modified 2026-06-17.