CVE-2022-47318: Debian Linux
High severity, CVSS 8.0. EPSS: 1.4% chance of exploitation in the next 30 days.
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.
Affected products
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 37 only
- Ruby-Git Project Ruby-Git: before 1.13.0 (fixed in 1.13.0)
Published 2023-01-17. Last modified 2026-06-17.