CVE-2022-4890

A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The patch is named b067372f3ee26fe1b657121f0f41883ff4461a06. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218387.
Configurations

Configuration 1 (hide)

cpe:2.3:a:predictapp_project:predictapp:*:*:*:*:*:*:*:*

History

29 Feb 2024, 01:36

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue encontrada en abhilash1985 PredictApp y clasificada como crítica. Este problema afecta un procesamiento desconocido del archivo config/initializers/new_framework_defaults_7_0.rb del componente Cookie Handler. La manipulación conduce a la deserialización. El ataque puede iniciarse de forma remota. El parche se llama b067372f3ee26fe1b657121f0f41883ff4461a06. Se recomienda aplicar un parche para solucionar este problema. El identificador asociado de esta vulnerabilidad es VDB-218387.

04 Nov 2023, 02:26

Type Values Removed Values Added
References (MISC) https://vuldb.com/?ctiid.218387 - Third Party Advisory (MISC) https://vuldb.com/?ctiid.218387 - Permissions Required
References (MISC) https://vuldb.com/?id.218387 - Third Party Advisory (MISC) https://vuldb.com/?id.218387 - Permissions Required
CWE CWE-502

20 Oct 2023, 15:15

Type Values Removed Values Added
CWE CWE-502
Summary A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The name of the patch is b067372f3ee26fe1b657121f0f41883ff4461a06. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218387. A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The patch is named b067372f3ee26fe1b657121f0f41883ff4461a06. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218387.

24 Jan 2023, 16:19

Type Values Removed Values Added
First Time Predictapp Project predictapp
Predictapp Project
CPE cpe:2.3:a:predictapp_project:predictapp:*:*:*:*:*:*:*:*
References (MISC) https://github.com/abhilash1985/PredictApp/commit/b067372f3ee26fe1b657121f0f41883ff4461a06 - (MISC) https://github.com/abhilash1985/PredictApp/commit/b067372f3ee26fe1b657121f0f41883ff4461a06 - Patch, Third Party Advisory
References (MISC) https://github.com/abhilash1985/PredictApp/pull/73 - (MISC) https://github.com/abhilash1985/PredictApp/pull/73 - Patch, Third Party Advisory
References (MISC) https://vuldb.com/?id.218387 - (MISC) https://vuldb.com/?id.218387 - Third Party Advisory
References (MISC) https://vuldb.com/?ctiid.218387 - (MISC) https://vuldb.com/?ctiid.218387 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

16 Jan 2023, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-16 13:15

Updated : 2024-04-11 01:17


NVD link : CVE-2022-4890

Mitre link : CVE-2022-4890

CVE.ORG link : CVE-2022-4890


JSON object : View

Products Affected

predictapp_project

  • predictapp
CWE
CWE-502

Deserialization of Untrusted Data