CVE-2022-4890
CVSS V2 None
CVSS V3 None
Description
A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The name of the patch is b067372f3ee26fe1b657121f0f41883ff4461a06. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218387.
Overview
- CVE ID
- CVE-2022-4890
- Assigner
- cna@vuldb.com
- Vulnerability Status
- Analyzed
- Published Version
- 2023-01-16T13:15:10
- Last Modified Date
- 2023-01-24T16:19:48
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:predictapp_project:predictapp:*:*:*:*:*:*:*:* | 1 | OR | 2022-03-20 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2022-4890 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4890 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-01-16 14:14:46 | Added to TrackCVE | |||
2023-01-16 14:14:47 | Weakness Enumeration | new | ||
2023-01-17 14:15:08 | 2023-01-17T13:24:41 | CVE Modified Date | updated | |
2023-01-17 14:15:08 | Received | Awaiting Analysis | Vulnerability Status | updated |
2023-01-17 14:15:12 | CVSS V3 information | new | ||
2023-01-17 14:15:12 | CVSS V2 information | new | ||
2023-01-23 15:14:03 | Awaiting Analysis | Undergoing Analysis | Vulnerability Status | updated |
2023-01-23 15:14:07 | CVSS V3 information | new | ||
2023-01-23 15:14:07 | CVSS V2 information | new | ||
2023-01-24 18:12:46 | 2023-01-24T16:19:48 | CVE Modified Date | updated | |
2023-01-24 18:12:46 | Undergoing Analysis | Analyzed | Vulnerability Status | updated |
2023-01-24 18:12:49 | CPE Information | updated | ||
2023-01-24 18:12:50 | CVSS V3 information | new | ||
2023-01-24 18:12:50 | CVSS V2 information | new |