Описание
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.
Ссылки
- ExploitThird Party Advisory
- Exploit
- Patch
- ExploitPatchVendor Advisory
- Mailing ListThird Party Advisory
- Mailing List
- Mailing List
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Exploit
- Patch
- ExploitPatchVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing List
- Mailing List
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
Конфигурация 2Версия до 0.21.0 (исключая)
cpe:2.3:a:jnunemaker:httparty:*:*:*:*:*:ruby:*:*
EPSS
Процентиль: 78%
0.0119
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-472
Связанные уязвимости
CVSS3: 5.3
ubuntu
около 2 лет назад
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.
CVSS3: 5.3
debian
около 2 лет назад
httparty before 0.21.0 is vulnerable to an assumed-immutable web param ...
CVSS3: 6.5
github
около 3 лет назад
httparty has multipart/form-data request tampering vulnerability
EPSS
Процентиль: 78%
0.0119
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-472