CVE-2022-39219 - CVE House
Back to Database
Status published High CVE-2022-39219

Bifrost users using basic authntication can bypass write permission limit

Vulnerability Description

Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions to write requests when they are normally forbidden from doing so. Version 1.8.7-release contains a patch. There are currently no known workarounds.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-39219

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Bifrost
Vulnerable Versions:
< 1.8.7-release

Timeline

Official Publish: September 26th, 2022
Last Modified: April 22nd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

Weaknesses (CWE)