CVE-2022-3348 - CVE House
Back to Database
Status published Medium CVE-2022-3348

Exposure of Sensitive Information to an Unauthorized Actor in tooljet/tooljet

Vulnerability Description

Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a little bit more specific, because it is needed to be an editor in the same app as the victim.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3348

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

tooljet/tooljet
Vulnerable Versions:
unspecified

Timeline

Official Publish: September 28th, 2022
Last Modified: May 21st, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)