10
CVE-2022-30123
- EPSS 2.26%
- Published 05.12.2022 22:15:10
- Last modified 21.11.2024 07:02:12
- Source support@hackerone.com
- Teams watchlist Login
- Open Login
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
Data is provided by the National Vulnerability Database (NVD)
Rack Project ≫ Rack Version < 2.0.9.1
Rack Project ≫ Rack Version >= 2.1.0 < 2.1.4.1
Rack Project ≫ Rack Version >= 2.2.0 < 2.2.3.1
Debian ≫ Debian Linux Version11.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.26% | 0.84 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.