Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g47j-3m2m-74qv

Опубликовано: 04 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Duplicate Advisory: httparty has multipart/form-data request tampering vulnerability

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-5pq7-52mg-hr42. This link is maintained to preserve external references.

Original Description

httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.

Пакеты

Наименование

httparty

rubygems
Затронутые версииВерсия исправления

<= 0.20.0

Отсутствует

5.3 Medium

CVSS3

Дефекты

CWE-472
CWE-668

5.3 Medium

CVSS3

Дефекты

CWE-472
CWE-668