Known vulnerabilities in rubygem-thread_safe (Red Hat package)
Vendor:
Red Hat Inc.
Software:
rubygem-thread_safe (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:rubygem-thread_safe_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU68860 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2022-31163 |
CWE-22 | Medium | 0.3.6-1.el7rhgs | 31.10.2022 |
SB2022103147 SB2022103161 SB2022072942 and 6 more |
||
| #VU65835 - Incorrect Regular Expression CVE-2022-31129 |
CWE-185 | Medium | 0.3.6-1.el7rhgs | 27.07.2022 |
SB2022072729 SB2022072901 SB2022081048 and 102 more |
||
| #VU64863 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-30123 |
CWE-78 | High | 0.3.6-1.el7rhgs | 02.07.2022 |
SB2022070222 SB2022070430 SB2022072530 and 14 more |
||
| #VU64862 - Improper input validation CVE-2022-30122 |
CWE-20 | Medium | 0.3.6-1.el7rhgs | 02.07.2022 |
SB2022070222 SB2022070430 SB2022072530 and 8 more |
||
| #VU61798 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-24790 |
CWE-444 | Medium | 0.3.6-1.el7rhgs | 01.04.2022 |
SB2022040112 SB2022052603 SB2022092241 and 12 more |