Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-30123


A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.


Published

2022-12-05T22:15:10.280

Last Modified

2024-11-21T07:02:12.290

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 10.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-150
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rack_project rack < 2.0.9.1 Yes
Application rack_project rack < 2.1.4.1 Yes
Application rack_project rack < 2.2.3.1 Yes
Operating System debian debian_linux 11.0 Yes

References