Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-46648
HistoryJan 17, 2023 - 12:00 a.m.

CVE-2022-46648

2023-01-1700:00:00
ubuntu.com
ubuntu.com
21
ruby-git
remote code execution
authenticated
repository
filename
cve-2022-46648
unix
vulnerability different

CVSS3

8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

68.9%

ruby-git versions prior to v1.13.0 allows a remote authenticated attacker
to execute an arbitrary ruby code by having a user to load a repository
containing a specially crafted filename to the product. This vulnerability
is different from CVE-2022-47318.

CVSS3

8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

68.9%