Medium severity5.9NVD Advisory· Published Jun 9, 2022· Updated Jun 17, 2026
CVE-2022-31033
CVE-2022-31033
Description
The Mechanize library is used for automating interaction with websites. Mechanize automatically stores and sends cookies, follows redirects, and can follow links and submit forms. In versions prior to 2.8.5 the Authorization header is leaked after a redirect to a different port on the same site. Users are advised to upgrade to Mechanize v2.8.5 or later. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mechanizeRubyGems | < 2.8.5 | 2.8.5 |
Affected products
5cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- sparklemotion/mechanizev5Range: < 2.8.5
Patches
Vulnerability mechanics
References
7- github.com/sparklemotion/mechanize/commit/c7fe6996a5b95f9880653ba3bc548a8d4ef72317nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-64qm-hrgp-pgr9ghsaADVISORY
- github.com/sparklemotion/mechanize/security/advisories/GHSA-64qm-hrgp-pgr9nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-31033ghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/mechanize/CVE-2022-31033.ymlghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7OKZMR5O3T5HQ2V737TC7IU4WZRT2LGX/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OA2FJROTX2U6EBWDPKRQ2VAM67A5TQXF/nvd
News mentions
0No linked articles in our index yet.