10

CVE-2022-30123

A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rack Project ≫ Rack Version < 2.0.9.1
Rack Project ≫ Rack Version >= 2.1.0 < 2.1.4.1
Rack Project ≫ Rack Version >= 2.2.0 < 2.2.3.1
Debian ≫ Debian Linux Version 11.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.8% 0.757
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.

https://security.gentoo.org/glsa/202310-18
Third Party Advisory
https://www.debian.org/security/2023/dsa-5530
Third Party Advisory
https://discuss.rubyonrails.org/t/cve-2022-30123-possible-shell-escape-sequence-injection-vulnerability-in-rack/80728
Third Party Advisory
https://security.netapp.com/advisory/ntap-20231208-0011/