High severity7.2NVD Advisory· Published Feb 18, 2022· Updated May 18, 2026
CVE-2022-23650
CVE-2022-23650
Description
Netmaker is a platform for creating and managing virtual overlay networks using WireGuard. Prior to versions 0.8.5, 0.9.4, and 010.0, there is a hard-coded cryptographic key in the code base which can be exploited to run admin commands on a remote server if the exploiter know the address and username of the admin. This effects the server (netmaker) component, and not clients. This has been patched in Netmaker v0.8.5, v0.9.4, and v0.10.0. There are currently no known workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/gravitl/netmakerGo | < 0.8.5 | 0.8.5 |
github.com/gravitl/netmakerGo | >= 0.9.0, < 0.9.4 | 0.9.4 |
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/gravitl/netmaker/commit/3d4f44ecfe8be4ca38920556ba3b90502ffb4feenvdPatchThird Party AdvisoryWEB
- github.com/gravitl/netmaker/commit/e9bce264719f88c30e252ecc754d08f422f4c080nvdPatchThird Party AdvisoryWEB
- github.com/gravitl/netmaker/pull/781/commits/1bec97c662670dfdab804343fc42ae4b1d050a87nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-86f3-hf24-76q4ghsaADVISORY
- github.com/gravitl/netmaker/security/advisories/GHSA-86f3-hf24-76q4nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-23650ghsaADVISORY
News mentions
0No linked articles in our index yet.