VDB
CVE-2022-21831
CVE-2022-21831
PUBLISHED
Ruby on Rails ist ein in der Programmiersprache Ruby geschriebenes und quelloffenes Web Application Framework.
EPSS 1.42% · 80.9th percentile
Risk Scores
EPSS Score
1.42%
80.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | |
| Open Source | Open Source Ruby on Rails <6.1.4.7 | |
| SUSE | SUSE openSUSE | |
| Open Source | Open Source Ruby on Rails <5.2.6.3 | |
| Open Source | Open Source Ruby on Rails <7.0.2.3 | |
| Open Source | Open Source Ruby on Rails <6.0.4.7 |
Timeline
- CVE Published
- May 27, 2022 EPSS Score
- Jul 16, 2022 EPSS Score
- Sep 2, 2022 EPSS Score
- Sep 10, 2022 PoC Published
- Nov 19, 2022 EPSS Score
- Dec 9, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- May 4, 2023 EPSS Score
- Jun 2, 2023 EPSS Score
- Jul 28, 2023 PoC Published
- Aug 9, 2023 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2022/wid-sec-w-2022-1280.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-1280 advisory
- https://rubyonrails.org/2022/3/8/Rails-7-0-2-3-6-1-4-7-6-0-4-7-and-5-2-6-3-have-been-released advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00002.html advisory
- https://lists.debian.org/debian-security-announce/2023/msg00061.html advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/46EQRIAH3FLDMDVYDHYXRLAPYFUK6NA6/ advisory