Lucene search

K
osvGoogleOSV:CVE-2022-46648
HistoryJan 17, 2023 - 10:15 a.m.

CVE-2022-46648

2023-01-1710:15:11
Google
osv.dev
5
cve-2022-46648
remote code execution
authenticated attacker
specially crafted filename
repository
vulnerability
ruby-git
prior version

7.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.9%

ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318.