CVE-2022-46648
published 2023-01-17CVE-2022-46648: ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a…
PriorityP344high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
1.35%
68.8th percentile
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ruby-git | < ruby-git 1.13.1-1 (bookworm) | ruby-git 1.13.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| git | git | >= 0 < 1.13.0 | 1.13.0 |
| git | git | >= 1.2.0 < 1.13.0 | 1.13.0 |
| ruby-git | ruby-git | — | — |
| ruby-git | ruby-git | >= 0 < 1.7.0-1+deb11u1 | 1.7.0-1+deb11u1 |
| ruby-git | ruby-git | >= 0 < 1.13.1-1 | 1.13.1-1 |
| ruby-git | ruby-git | >= 0 < 1.13.1-1 | 1.13.1-1 |
| ruby-git | ruby-git | >= 0 < 1.13.1-1 | 1.13.1-1 |
| ruby-git_project | ruby-git | < 1.13.0 | 1.13.0 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
ghsa8.0HIGH
osv8.0HIGH
vendor_debian8.0HIGH
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ruby-git: code injection vulnerability
vendor_redhat·2023-01-05·CVSS 8.0
CVE-2022-46648 [HIGH] CWE-94 ruby-git: code injection vulnerability
ruby-git: code injection vulnerability
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318.
A flaw was found in the ruby-git package, which allows a remote authenticated attacker to execute arbitrary code on the system, caused by a code injection flaw. An attacker can execute arbitrary code on the system by using a specially-crafted filename in the repository.
Red Hat
ruby-git: code injection vulnerability
vendor_redhat·2023-01-05·CVSS 8.0
CVE-2022-47318 [HIGH] CWE-94 ruby-git: code injection vulnerability
ruby-git: code injection vulnerability
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.
A code injection flaw was found in the ruby-git package. This issue may allow a remote authenticated attacker to execute arbitrary code on the system by using a specially-crafted filename in the repository.
Debian
CVE-2022-46648: ruby-git - ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to exe...
vendor_debian·2022·CVSS 8.0
CVE-2022-46648 [HIGH] CVE-2022-46648: ruby-git - ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to exe...
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318.
Scope: local
bookworm: resolved (fixed in 1.13.1-1)
bullseye: resolved (fixed in 1.7.0-1+deb11u1)
forky: resolved (fixed in 1.13.1-1)
sid: resolved (fixed in 1.13.1-1)
trixie: resolved (fixed in 1.13.1-1)
Debian
CVE-2022-47318: ruby-git - ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to exe...
vendor_debian·2022·CVSS 8.0
CVE-2022-47318 [HIGH] CVE-2022-47318: ruby-git - ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to exe...
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.
Scope: local
bookworm: resolved (fixed in 1.13.1-1)
bullseye: resolved (fixed in 1.7.0-1+deb11u1)
forky: resolved (fixed in 1.13.1-1)
sid: resolved (fixed in 1.13.1-1)
trixie: resolved (fixed in 1.13.1-1)
OSV
CVE-2022-47318: ruby-git versions prior to v1
osv·2023-01-17·CVSS 8.0
CVE-2022-47318 [HIGH] CVE-2022-47318: ruby-git versions prior to v1
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.
OSV
CVE-2022-46648: ruby-git versions prior to v1
osv·2023-01-17·CVSS 8.0
CVE-2022-46648 [HIGH] CVE-2022-46648: ruby-git versions prior to v1
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318.
GHSA
Code injection in ruby git
ghsa·2023-01-17·CVSS 8.0
CVE-2022-47318 [HIGH] CWE-94 Code injection in ruby git
Code injection in ruby git
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.
OSV
Code injection in ruby git
osv·2023-01-17·CVSS 8.0
CVE-2022-47318 [HIGH] Code injection in ruby git
Code injection in ruby git
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.
OSV
ruby-git has potential remote code execution vulnerability
osv·2023-01-09
CVE-2022-46648 [HIGH] ruby-git has potential remote code execution vulnerability
ruby-git has potential remote code execution vulnerability
The git gem, between versions 1.2.0 and 1.12.0, incorrectly parsed the output of the `git ls-files` command using `eval()` to unescape quoted file names. If a file name was added to the git repository contained special characters, such as `\n`, then the `git ls-files` command would print the file name in quotes and escape any special characters. If the `Git#ls_files` method encountered a quoted file name it would use `eval()` to unquote and unescape any special characters, leading to potential remote code execution. Version 1.13.0 of the git gem was released which correctly parses any quoted file names.
GHSA
ruby-git has potential remote code execution vulnerability
ghsa·2023-01-09
CVE-2022-46648 [HIGH] CWE-94 ruby-git has potential remote code execution vulnerability
ruby-git has potential remote code execution vulnerability
The git gem, between versions 1.2.0 and 1.12.0, incorrectly parsed the output of the `git ls-files` command using `eval()` to unescape quoted file names. If a file name was added to the git repository contained special characters, such as `\n`, then the `git ls-files` command would print the file name in quotes and escape any special characters. If the `Git#ls_files` method encountered a quoted file name it would use `eval()` to unquote and unescape any special characters, leading to potential remote code execution. Version 1.13.0 of the git gem was released which correctly parses any quoted file names.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ruby-git/ruby-githttps://github.com/ruby-git/ruby-git/pull/602https://jvn.jp/en/jp/JVN16765254/index.htmlhttps://lists.debian.org/debian-lts-announce/2023/01/msg00043.htmlhttps://github.com/ruby-git/ruby-githttps://github.com/ruby-git/ruby-git/pull/602https://jvn.jp/en/jp/JVN16765254/index.htmlhttps://lists.debian.org/debian-lts-announce/2023/01/msg00043.html
2023-01-17
Published