peter bassill · operator
$ cve CVE-2022-44268 JSON

CVE-2022-44268 EXPLOIT

6.5
MEDIUM · CVSS 3.1 · EPSS 89.9% (pctl 100)

Patch early

A public exploit exists.

Description

ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS89.86% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2023-02-06
Last modified2026-06-17

Affected (1)

VendorProduct
imagemagickimagemagick

Public exploits

SourceTitleDate
exploit-dbImageMagick 7.1.0-49 - Arbitrary File Read2023-04-05

References

→ the Explorer  ·  watch your stack  ·  NVD