httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3716-1 | ruby-httparty security update |
Debian DLA |
DLA-3900-1 | ruby-httparty security update |
EUVD |
EUVD-2023-0342 | httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written. |
Github GHSA |
GHSA-5pq7-52mg-hr42 | httparty has multipart/form-data request tampering vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 03 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written. | httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written. |
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-06-03T14:42:07.312Z
Reserved: 2024-01-04T18:44:53.108Z
Link: CVE-2024-22049
Updated: 2024-09-28T12:03:40.887Z
Status : Modified
Published: 2024-01-04T21:15:10.013
Modified: 2025-06-03T15:15:56.780
Link: CVE-2024-22049
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA