abhilash1985 PredictApp Cookie new_framework_defaults_7_0.rb deserialization
Published Jan 16, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.79%
Description
A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The patch is named b067372f3ee26fe1b657121f0f41883ff4461a06. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218387.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Abhilash1985 | PredictApp | n/a |
|
- < 2022-03-20
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-52148 Advisory
- https://github.com/abhilash1985/PredictApp/commit/b067372f3ee26fe1b657121f0f41883ff4461a06 patch
- https://github.com/abhilash1985/PredictApp/pull/73 issue-trackingPatch
- https://vuldb.com/?ctiid.218387 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.218387 vdb-entrytechnical-descriptionPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-52148 | Advisory | |
| https://github.com/abhilash1985/PredictApp/commit/b067372f3ee26fe1b657121f0f41883ff4461a06 | patch | |
| https://github.com/abhilash1985/PredictApp/pull/73 | issue-trackingPatch | |
| https://vuldb.com/?ctiid.218387 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.218387 | vdb-entrytechnical-descriptionPermissions Required |
Change history (0)
No recorded changes yet.