PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2022-25237

9.8
CVSS
Description

Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Updated Sep 18, 2026View on NVD →
S4E scanner

Bonita Web 2021.2 - Authentication/Authorization Bypass

Bonita Web 2021.2 contains an authentication/authorization bypass vulnerability caused by an overly broad exclude pattern in RestAPIAuthorizationFilter, allowing unauthenticated users to access privileged API endpoints by appending ;i18ntranslation or /../i18ntranslation/ to the URL. References: https://nvd.nist.gov/vuln/detail/CVE-2022-25237 https://rhinosecuritylabs.com/application-security/cve-2022-25237-bonitasoft-authorization-bypass/ https://bonitasoft.com/ Remediation: Update Bonita Web to the latest version that addresses this vulnerability or implement proper access controls to restrict unauthorized API access.

Used 2.3k times · domain, subdomain, ipv4

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →