CVE Feed

    Dashboard / CVE / CVE-2022-31149

    CVE-2022-31149

    ActivityWatch open-source automated time tracker. Versions prior to 0.12.0b2 are vulnerable to DNS rebinding attacks. This vulnerability impacts everyone running ActivityWatch and gives the attacker full access to the ActivityWatch REST API. Users should upgrade to v0.12.0b2 or later to receive a patch. As a workaround, block DNS lookups that resolve to 127.0.0.1.

    Published:Sep 7, 2022
    Last Modified:Apr 22, 2025
    EPS:Sep 7, 2022
    EPSS Score:0.00436
    CVSS Score:8.8

    Affected Products

    Vendor
    Activitywatch
    Product
    Activitywatch

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High