Medium severity6.5NVD Advisory· Published Dec 20, 2022· Updated Jun 17, 2026
CVE-2022-47551
CVE-2022-47551
Description
Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The root cause of the issue is the Apiman project's accidental acceptance of a large contribution that was not fully compatible with the security model of Apiman versions before 3.0.0.Final. Because of this, 3.0.0.Final is not affected by the vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.apiman:apiman-manager-api-rest-implMaven | >= 1.5.7, < 3.0.0.Final | 3.0.0.Final |
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-54r5-wr8x-x5v3ghsaADVISORY
- github.com/advisories/GHSA-j94p-hv25-rm5gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-47551ghsaADVISORY
- www.apiman.io/blog/permissions-bypass-disclosure/nvdVendor Advisory
- github.com/apiman/apiman/security/advisories/GHSA-j94p-hv25-rm5gghsaWEB
- www.apiman.io/blog/permissions-bypass-disclosureghsaWEB
News mentions
0No linked articles in our index yet.