Lucene search

K
rubygemsRubySecRUBY:GIT-2022-47318
HistoryJan 16, 2023 - 9:00 p.m.

Code injection in ruby git

2023-01-1621:00:00
RubySec
rubysec.com
9
ruby-git
code injection
remote attacker
vulnerability

8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

51.2%

ruby-git versions prior to v1.13.0 allows a remote authenticated attacker
to execute an arbitrary ruby code by having a user to load a repository containing
a specially crafted filename to the product. This vulnerability is different from
CVE-2022-46648.

CPENameOperatorVersion
gitlt1.13.0

8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

51.2%