Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-33241 | Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included execution of Python or JavaScript code. In other words, Code by Zapier was providing a customer-controlled general-purpose virtual machine that unintentionally granted full access to all users of a company's account, but was supposed to enforce role-based access control within that company's account. Before 2022-08-17, a customer could have resolved this by (in effect) using a separate virtual machine for an application that held credentials - or other secrets - that weren't supposed to be shared among all of its employees. (Multiple accounts would have been needed to operate these independent virtual machines.) |
Tue, 27 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-27T20:10:19.291Z
Reserved: 2022-04-08T00:00:00.000Z
Link: CVE-2022-28802
Updated: 2024-08-03T06:03:53.046Z
Status : Modified
Published: 2022-09-21T20:15:10.027
Modified: 2025-05-27T20:15:22.553
Link: CVE-2022-28802
No data.
OpenCVE Enrichment
No data.
EUVD