CVE-2022-4890

A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The patch is named b067372f3ee26fe1b657121f0f41883ff4461a06. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218387.
Configurations

Configuration 1 (hide)

cpe:2.3:a:predictapp_project:predictapp:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:36

Type Values Removed Values Added
References () https://github.com/abhilash1985/PredictApp/commit/b067372f3ee26fe1b657121f0f41883ff4461a06 - Patch () https://github.com/abhilash1985/PredictApp/commit/b067372f3ee26fe1b657121f0f41883ff4461a06 - Patch
References () https://github.com/abhilash1985/PredictApp/pull/73 - Patch () https://github.com/abhilash1985/PredictApp/pull/73 - Patch
References () https://vuldb.com/?ctiid.218387 - Permissions Required () https://vuldb.com/?ctiid.218387 - Permissions Required
References () https://vuldb.com/?id.218387 - Permissions Required () https://vuldb.com/?id.218387 - Permissions Required
CVSS v2 : 6.5
v3 : 9.8
v2 : 6.5
v3 : 6.3

04 Nov 2023, 02:26

Type Values Removed Values Added
References (MISC) https://vuldb.com/?id.218387 - Third Party Advisory (MISC) https://vuldb.com/?id.218387 - Permissions Required
References (MISC) https://vuldb.com/?ctiid.218387 - Third Party Advisory (MISC) https://vuldb.com/?ctiid.218387 - Permissions Required
CWE CWE-502

20 Oct 2023, 15:15

Type Values Removed Values Added
CWE CWE-502
Summary A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The name of the patch is b067372f3ee26fe1b657121f0f41883ff4461a06. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218387. A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The patch is named b067372f3ee26fe1b657121f0f41883ff4461a06. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218387.

Information

Published : 2023-01-16 13:15

Updated : 2024-11-21 07:36


NVD link : CVE-2022-4890

Mitre link : CVE-2022-4890

CVE.ORG link : CVE-2022-4890


JSON object : View

Products Affected

predictapp_project

  • predictapp
CWE
CWE-502

Deserialization of Untrusted Data