7.5
CVSSv2

CVE-2022-1212

Published: 05/04/2022 Updated: 12/04/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby before 3.2. Possible arbitrary code execution if being exploited.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mruby mruby

mruby mruby 3.1.0

Vendor Advisories

Debian Bug report logs - #1009044 mruby: CVE-2022-1212 - Use-After-Free in str_escape Package: src:mruby; Maintainer for src:mruby is Nobuhiro Iwamatsu <iwamatsu@debianorg>; Reported by: Neil Williams <codehelp@debianorg> Date: Wed, 6 Apr 2022 13:33:02 UTC Severity: important Tags: fixed-upstream, security, upstre ...