Skip to content

Conversation

@postmodern
Copy link
Member

@postmodern postmodern commented Jan 8, 2023

This CVE is reserved but not public yet, but the vulnerability has been fixed via a pull request and version 1.13.0 of the git gem has been released.

The only other information I could find on CVE-2022-46648 are:

* This CVE is reserved but not public yet, but the vulnerability has
  been fixed via a pull request and version 1.13.0 of the git gem has
  been released.
* The only other information I could find on CVE-2022-46648 are:
  * https://jvn.jp/jp/JVN16765254/index.html
  * https://www.cybersecurity-help.cz/vdb/SB2023010501
    * Note, their vulnerable version range is incorrect. I checked the
      version tags for ruby-git, and `eval()` was added in 1.2.0.
      Versions prior to 1.2.0 do not have the `eval()`.
      ruby-git/ruby-git@ee90922
@postmodern postmodern merged commit 12ebb6d into master Jan 8, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants