Lucene search

K
cvelistHackeroneCVELIST:CVE-2022-21831
HistoryMay 26, 2022 - 12:00 a.m.

CVE-2022-21831

2022-05-2600:00:00
CWE-94
hackerone
www.cve.org
2
code injection
active storage
vulnerability
image processing
executable code

AI Score

9.7

Confidence

High

EPSS

0.048

Percentile

92.8%

A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "https://github.com/rails/rails",
    "versions": [
      {
        "version": "7.0.2.3, 6.1.4.7, 6.0.4.7, 5.2.6.3",
        "status": "affected"
      }
    ]
  }
]

AI Score

9.7

Confidence

High

EPSS

0.048

Percentile

92.8%