cbcvebase.
CVE-2022-47318
published 2023-01-17

CVE-2022-47318: ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a…

PriorityP344high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
1.36%
69.0th percentile
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianruby-git< ruby-git 1.13.1-1 (bookworm)ruby-git 1.13.1-1 (bookworm)
fedoraprojectfedora
gitgit>= 0 < 1.13.01.13.0
ruby-gitruby-git
ruby-gitruby-git>= 0 < 1.7.0-1+deb11u11.7.0-1+deb11u1
ruby-gitruby-git>= 0 < 1.13.1-11.13.1-1
ruby-gitruby-git>= 0 < 1.13.1-11.13.1-1
ruby-gitruby-git>= 0 < 1.13.1-11.13.1-1
ruby-git_projectruby-git< 1.13.01.13.0

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
ghsa8.0HIGH
osv8.0HIGH
vendor_debian8.0HIGH
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.