4.3
CVSSv3

CVE-2022-45301

Published: 29/11/2022 Updated: 01/12/2022
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

chocolatey chocolatey ruby