← Back to CVE List

CVE-2024-22049

Published: 2024-01-04T21:15Z
Last Modified: 2025-02-13T18:16Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt