VYPR
Medium severity4.3NVD Advisory· Published Nov 29, 2022· Updated Jun 17, 2026

CVE-2022-45301

CVE-2022-45301

Description

Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder.

Affected products

3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.