PT-2022-7287 · Ruby-Git+3 · Ruby-Git+3
Yuki Kokubun
·
Published
2022-01-05
·
Updated
2025-12-15
·
CVE-2022-47318
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ruby-git versions prior to v1.13.0
Description
The issue is related to incorrect code generation management in the Ruby/Git library, allowing a remote authenticated attacker to execute arbitrary Ruby code. This can be achieved by having a user load a repository containing a specially crafted filename to the product.
Recommendations
For versions prior to v1.13.0, update to version v1.13.0 or later to resolve the issue. As a temporary workaround, consider restricting access to repositories that may contain specially crafted filenames until the update is applied.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Rocky Linux
Ruby-Git