Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False-Positive: CVE-2022-3704 #250

Open
prabhu opened this issue Feb 13, 2024 · 0 comments
Open

False-Positive: CVE-2022-3704 #250

prabhu opened this issue Feb 13, 2024 · 0 comments
Labels
false-positive A wrongly identified vulnerability

Comments

@prabhu
Copy link
Member

prabhu commented Feb 13, 2024

PURL of wrongly matched component

pkg:gem/rails@7.0.8

Depscan findings

Other than the phrase wrongly reported as a security vulnerability, there is nothing in the API or attributes that give us the clue that this CVE is withdrawn.

https://github.com/AppThreat/vuln-list/blob/main/nvd/2022/CVE-2022-3704.json

A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The real existence of this vulnerability is still doubted at the moment. The name of the patch is be177e4566747b73ff63fd5f529fab564e475ed4. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-212319. NOTE: Maintainer declares that there isn’t a valid attack vector. The issue was wrongly reported as a security vulnerability by a non-member of the Rails team.
@prabhu prabhu added the false-positive A wrongly identified vulnerability label Feb 13, 2024
@prabhu prabhu assigned prabhu and cerrussell and unassigned prabhu and cerrussell Feb 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
false-positive A wrongly identified vulnerability
Projects
None yet
Development

No branches or pull requests

2 participants