CVE-2022-1212: Use-After-Free in str_escape in mruby/mruby in mruby/mruby
Published Apr 5, 2022
·Updated
Use-After-Free in strescape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
Affected Software
3 affected components
mruby mruby<=3.0.0
mruby mruby=3.1.0-rc
mruby mruby=3.1.0-rc2
Remediation
Event History
Apr 5, 2022
CVE Published
via MITRE·03:45 AM
Data Sourced
via MITRE·03:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-1212.
2
What is the severity of CVE-2022-1212?
CVE-2022-1212 has a severity rating of 9.8 (critical).
3
What software versions are affected by CVE-2022-1212?
CVE-2022-1212 affects mruby/mruby versions prior to 3.2.
4
Is arbitrary code execution possible with CVE-2022-1212?
Yes, arbitrary code execution is possible if CVE-2022-1212 is exploited.
5
How do I fix CVE-2022-1212?
To fix CVE-2022-1212, update mruby/mruby to version 3.2 or above.