CVE-2024-22049
MEDIUMDescription
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.
Is your site exposed to CVE-2024-22049?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| debian | debian_linux |
| debian | debian_linux |
| fedoraproject | fedora |
| fedoraproject | fedora |
| jnunemaker | httparty |
References
Advisories & Patches
Exploits
Other References
Frequently Asked Questions
What is CVE-2024-22049? +
How severe is CVE-2024-22049? +
What products are affected by CVE-2024-22049? +
How do I check if I'm vulnerable to CVE-2024-22049? +
Related Vulnerabilities
A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. When …
SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter.
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such …
QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the …
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the …