Описание
CSV-Safe improperly filters special characters potentially leading to CSV injection
CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-28481
- https://github.com/zvory/csv-safe/issues/7
- https://github.com/zvory/csv-safe/pull/8
- https://github.com/WeblateOrg/weblate/commit/d9e136ff228e3760fd6dd7572869ac38e9a81809
- https://hackerone.com/reports/223999
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/csv-safe/CVE-2022-28481.yml
Пакеты
Наименование
csv-safe
rubygems
Затронутые версииВерсия исправления
< 3.0.0
3.0.0
Связанные уязвимости
CVSS3: 9.8
nvd
почти 4 года назад
CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.