CVE Vulnerabilities

CVE-2022-47318

Published: Jan 17, 2023 | Modified: Apr 04, 2025
CVSS 3.x
8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.

Affected Software

NameVendorStart VersionEnd Version
Ruby-gitRuby-git_project*1.13.0 (excluding)
Red Hat Satellite 6.11 for RHEL 7RedHattfm-rubygem-git-0:1.18.0-0.1.el7sat*
Red Hat Satellite 6.11 for RHEL 8RedHattfm-rubygem-git-0:1.18.0-0.1.el8sat*
Red Hat Satellite 6.12 for RHEL 8RedHattfm-rubygem-git-0:1.18.0-1.el8sat*
Red Hat Satellite 6.13 for RHEL 8RedHattfm-rubygem-git-0:1.18.0-1.el8sat*
Red Hat Satellite 6.14 for RHEL 8RedHattfm-rubygem-git-0:1.18.0-1.el8sat*
Ruby-gitUbuntubionic*
Ruby-gitUbuntuesm-apps/bionic*
Ruby-gitUbuntuesm-apps/focal*
Ruby-gitUbuntuesm-apps/jammy*
Ruby-gitUbuntuesm-apps/xenial*
Ruby-gitUbuntufocal*
Ruby-gitUbuntujammy*
Ruby-gitUbuntukinetic*
Ruby-gitUbuntutrusty*
Ruby-gitUbuntuupstream*
Ruby-gitUbuntuxenial*

References