CVE-2024-22049
published 2024-01-04CVE-2024-22049: httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.29%
67.0th percentile
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ruby-httparty | < ruby-httparty 0.21.0-1 (bookworm) | ruby-httparty 0.21.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jnunemaker | httparty | < 0.21.0 | 0.21.0 |
| jnunemaker | httparty | >= 0 < 0.21.0 | 0.21.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-22049: httparty before 0
osv·2024-01-04·CVSS 5.3
CVE-2024-22049 [MEDIUM] CVE-2024-22049: httparty before 0
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.
OSV
httparty has multipart/form-data request tampering vulnerability
osv·2023-01-03
CVE-2024-22049 [MEDIUM] httparty has multipart/form-data request tampering vulnerability
httparty has multipart/form-data request tampering vulnerability
### Impact
I found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
`httparty/lib/httparty/request` > `body.rb` > `def generate_multipart`
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
By exploiting this problem, the following attacks are possible
* An attack that rewrites the "name" field according to the crafted file name, impersonating (overwriting) another field.
* Attacks that rewrite the filename extension at the time multipart/form-data is generated by tampering with the filename
For example, this vulnerability can be exploited to generate the following Content-Dispos
GHSA
httparty has multipart/form-data request tampering vulnerability
ghsa·2023-01-03
CVE-2024-22049 [MEDIUM] CWE-472 httparty has multipart/form-data request tampering vulnerability
httparty has multipart/form-data request tampering vulnerability
### Impact
I found "multipart/form-data request tampering vulnerability" caused by Content-Disposition "filename" lack of escaping in httparty.
`httparty/lib/httparty/request` > `body.rb` > `def generate_multipart`
https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43
By exploiting this problem, the following attacks are possible
* An attack that rewrites the "name" field according to the crafted file name, impersonating (overwriting) another field.
* Attacks that rewrite the filename extension at the time multipart/form-data is generated by tampering with the filename
For example, this vulnerability can be exploited to generate the following Content-Dispos
Debian
CVE-2024-22049: ruby-httparty - httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulne...
vendor_debian·2024·CVSS 5.3
CVE-2024-22049 [MEDIUM] CVE-2024-22049: ruby-httparty - httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulne...
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.
Scope: local
bookworm: resolved (fixed in 0.21.0-1)
bullseye: resolved (fixed in 0.18.1-2+deb11u1)
forky: resolved (fixed in 0.21.0-1)
sid: resolved (fixed in 0.21.0-1)
trixie: resolved (fixed in 0.21.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/advisories/GHSA-5pq7-52mg-hr42https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43https://github.com/jnunemaker/httparty/commit/cdb45a678c43e44570b4e73f84b1abeb5ec22b8ehttps://github.com/jnunemaker/httparty/security/advisories/GHSA-5pq7-52mg-hr42https://lists.debian.org/debian-lts-announce/2024/01/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/4LDGAVPR4KB72V4GGQCWODEAI72QZI3V/https://lists.fedoraproject.org/archives/list/[email protected]/message/IOWECZPJY6JZIA5FSBJR77KCRDXWDZDA/https://vulncheck.com/advisories/vc-advisory-GHSA-5pq7-52mg-hr42https://github.com/advisories/GHSA-5pq7-52mg-hr42https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43https://github.com/jnunemaker/httparty/commit/cdb45a678c43e44570b4e73f84b1abeb5ec22b8ehttps://github.com/jnunemaker/httparty/security/advisories/GHSA-5pq7-52mg-hr42https://lists.debian.org/debian-lts-announce/2024/01/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00043.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/4LDGAVPR4KB72V4GGQCWODEAI72QZI3V/https://lists.fedoraproject.org/archives/list/[email protected]/message/IOWECZPJY6JZIA5FSBJR77KCRDXWDZDA/https://vulncheck.com/advisories/vc-advisory-GHSA-5pq7-52mg-hr42
2024-01-04
Published