VulnerabilityModified
CVE-2022-45301
Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder.
MEDIUM 4.3EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- chocolatey/chocolatey ruby
- Source
- cve@mitre.org
References
- https://github.com/ycdxsb/Vuln/blob/main/ruby-weak-permission-vuln/ruby-weak-permission-vuln.mdBroken Link, Third Party Advisory
- https://github.com/ycdxsb/Vuln/blob/main/ruby-weak-permission-vuln/ruby-weak-permission-vuln.mdBroken Link, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.