Vulnerability record · CVE-2022-25237 · published 2 June 2022
CVE-2022-25237: Bonita Web RestAPIAuthorizationFilter auth bypass via URL suffix
Bonitasoft · Bonita Web
Bonita Web 2021.2 uses an overly broad exclude pattern in its RestAPIAuthorizationFilter, so appending ;i18ntranslation or /../i18ntranslation/ to a URL lets unprivileged users reach privileged API endpoints. Because those privileged API actions can be abused, the bypass can escalate to remote code execution.
Description
Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, and the bypass can lead to remote code execution.
What it is
Bonita Web 2021.2 uses an overly broad exclude pattern in its RestAPIAuthorizationFilter, so appending ;i18ntranslation or /../i18ntranslation/ to a URL lets unprivileged users reach privileged API endpoints. Because those privileged API actions can be abused, the bypass can escalate to remote code execution.
Impact
An attacker with no privileges gains access to privileged API functionality and can potentially execute remote code on the server.
Attack surface
Reachable over the network through crafted HTTP requests to the REST API; the CVSS vector shows no authentication and no user interaction required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.56449 (99th percentile) and references carry an Exploit tag, indicating public exploit detail exists.
What to do
- Upgrade Bonita Web to a version where the RestAPIAuthorizationFilter exclude pattern is fixed; the record does not name fixed versions, so confirm with Bonitasoft.
- Restrict network access to the Bonita REST API to trusted clients only.
- Review and tighten URL filter/authorization rules so path suffixes such as ;i18ntranslation and /../ cannot bypass checks.
- Audit accounts and API actions for unexpected privileged calls and remove unnecessary privileges.
Detection
- Search web/proxy logs for requests containing ;i18ntranslation or /../i18ntranslation/ in the URL.
- Alert on privileged REST API calls made by low-privilege or unauthenticated sessions.
- Monitor for unusual API actions that could lead to code execution, such as script or process-related endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/bonitasoft/bonita-web | ProductThird Party Advisory |
| https://rhinosecuritylabs.com/application-security/cve-2022-25237-bonitasoft-authorization-bypass/ | ExploitThird Party Advisory |
| https://github.com/bonitasoft/bonita-web | ProductThird Party Advisory |
| https://rhinosecuritylabs.com/application-security/cve-2022-25237-bonitasoft-authorization-bypass/ | ExploitThird Party Advisory |
Track CVE-2022-25237 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-25237), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.