Medium severity6.5NVD Advisory· Published Nov 22, 2022· Updated Jun 17, 2026
CVE-2022-4111
CVE-2022-4111
Description
Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures over 2MB.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tooljetnpm | < 1.27.0 | 1.27.0 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/tooljet/tooljet/commit/01cd3f0464747973ec329e9fb1ea12743d3235ccnvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/5596d072-66d2-4361-8cac-101c9c781c3dnvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-hgp8-w8fj-r4cmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-4111ghsaADVISORY
- github.com/ToolJet/ToolJet/pull/4103ghsaWEB
News mentions
0No linked articles in our index yet.