Advisories ยป MGASA-2023-0097

Updated ruby-git packages fix security vulnerability

Publication date: 18 Mar 2023
Modification date: 18 Mar 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-46648 , CVE-2022-47318

Description

ruby-git versions prior to v1.13.0 allows a remote authenticated attacker
to execute an arbitrary ruby code by having a user to load a repository
containing a specially crafted filename to the product. (CVE-2022-46648,
CVE-2022-47318)
                

References

SRPMS

8/core