{"id":"CVE-2022-45473","details":"In drachtio-server 0.8.18, /var/log/drachtio has mode 0777 and drachtio.log has mode 0666.","modified":"2026-08-13T14:07:39.402321Z","published":"2022-11-18T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/45xxx/CVE-2022-45473.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/45xxx/CVE-2022-45473.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-45473"},{"type":"REPORT","url":"https://github.com/drachtio/drachtio-server/issues/241"},{"type":"FIX","url":"https://github.com/drachtio/drachtio-server/commit/f791a9313c58a911ce09f465f4bba594243b29ec"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/drachtio/drachtio-server","events":[{"introduced":"0be8dc5c9f8414e226cd4f70e22a224cbea0a281"},{"fixed":"f791a9313c58a911ce09f465f4bba594243b29ec"}],"database_specific":{"cpe":"cpe:2.3:a:drachtio:drachtio-server:0.8.18:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.8.18"},{"last_affected":"0.8.18"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.8.18","v0.8.19-rc11","v0.8.19-rc10","v0.8.19-rc9","v0.8.19-rc8","v0.8.19-rc7","v0.8.19-rc6","v0.8.19-rc5","v0.8.19-rc4","v0.8.19-rc3","v0.8.19-rc2","v0.8.19-rc1","v0.8.18-rc8","v0.8.18"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-45473.json","vanir_signatures_modified":"2026-08-13T14:07:39Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"279164392971030361708973254568520296714","length":2961},"id":"CVE-2022-45473-28be088e","signature_type":"Function","signature_version":"v1","source":"https://github.com/drachtio/drachtio-server/commit/f791a9313c58a911ce09f465f4bba594243b29ec","target":{"file":"src/controller.cpp","function":"DrachtioController::initializeLogging"}},{"source":"https://github.com/drachtio/drachtio-server/commit/f791a9313c58a911ce09f465f4bba594243b29ec","target":{"file":"src/controller.cpp"},"deprecated":false,"digest":{"line_hashes":["128786794970971519645161226961061554769","251332460236910435058708065435141975164","134814881160439176525577656605802544401","55823422601767231424242581121953402649","124319992402858262129121201388676235373","236544655868235927516097746636193911291","152195083367639672409893081370435156642","154855900410144201373659356347792263639"],"threshold":0.9},"id":"CVE-2022-45473-a3964cc4","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}