VYPR
Medium severity5.3OSV Advisory· Published Jan 4, 2024· Updated Jul 14, 2026

CVE-2024-22049

CVE-2024-22049

Description

httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
httpartyRubyGems
< 0.21.00.21.0

Affected products

7
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
  • cpe:2.3:a:jnunemaker:httparty:*:*:*:*:*:ruby:*:*+ 1 more
    • cpe:2.3:a:jnunemaker:httparty:*:*:*:*:*:ruby:*:*range: <0.21.0
    • (no CPE)range: v0, v0.10.0, v0.10.1, …
  • ghsa-coords
    Range: < 0.21.0

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.