CVE-2022-30123
Summary
| CVE | CVE-2022-30123 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-05 22:15:00 UTC |
| Updated | 2023-12-08 22:15:00 UTC |
| Description | A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Application | Rack Project | Rack | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-5530-1 ruby-rack | DEBIAN | www.debian.org | |
| CVE-2022-30123 Rack Vulnerability in NetApp Products | NetApp Product Security | security.netapp.com | ||
| Rack: Multiple Vulnerabilities (GLSA 202310-18) — Gentoo security | GENTOO | security.gentoo.org | |
| [CVE-2022-30123] Possible shell escape sequence injection vulnerability in Rack - Security Announcements - Ruby on Rails Discussions | MISC | discuss.rubyonrails.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160196 Oracle Enterprise Linux Security Update for pcs (ELSA-2022-7343)
- 180992 Debian Security Update for ruby-rack (DLA 3095-1)
- 182458 Debian Security Update for ruby-rack (CVE-2022-30123)
- 199506 Ubuntu Security Notification for Rack Vulnerabilities (USN-5896-1)
- 240808 Red Hat Update for pcs (RHSA-2022:7343)
- 354136 Amazon Linux Security Advisory for pcs : ALAS2-2022-1895
- 377817 Alibaba Cloud Linux Security Update for pcs (ALINUX2-SA-2022:0056)
- 6000290 Debian Security Update for ruby-rack (DSA 5530-1)
- 710780 Gentoo Linux Rack Multiple Vulnerabilities (GLSA 202310-18)
- 753402 SUSE Enterprise Linux Security Update for rubygem-rack (SUSE-SU-2022:2192-1)