RubySec

Providing security resources for the Ruby community

CVE-2022-1812 (publify_core): Integer overflow in publify_core

Integer overflow in publify_core

Published: January 14, 2023

SECURITY IDENTIFIERS

GEM

publify_core

SEVERITY

CVSS v3.x: 9.8 (Critical)

PATCHED VERSIONS

>= 9.2.10

DESCRIPTION

Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10 due to an unlimited length user name field.

RELATED