CVE-2022-36231
CRITICAL9.8EPSS 22.6%Code injection in pdf_info
Published: 2/24/2023Modified: 3/13/2025
Description
pdf_info 0.5.3 is vulnerable to Command Execution. An attacker using a specially crafted payload may execute OS commands by using command chaining because during object initalization there is no validation performed and the user provided path is used.
Affected packages (1)
- RubyGems/pdf_infofrom 0, <= 0.5.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-36231
- PATCHhttps://github.com/newspaperclub/pdf_info
- WEBhttps://github.com/affix/CVE-2022-36231
- WEBhttps://github.com/newspaperclub/pdf_info/issues/16
- WEBhttps://github.com/newspaperclub/pdf_info/pull/15
- WEBhttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/pdf_info/CVE-2022-36231.yml
- WEBhttps://rubygems.org/gems/pdf_info