First published: Tue Nov 29 2022(Updated: )
Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chocolatey Ruby | <=3.1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45301 has been classified as a high-severity vulnerability due to insecure permissions allowing unauthorized write access.
To fix CVE-2022-45301, update the Chocolatey Ruby package to version 3.1.2.2 or later.
CVE-2022-45301 affects all installations of Chocolatey Ruby version 3.1.2.1 and below.
CVE-2022-45301 could allow malicious users to modify files in the C:\tools\ruby31 directory, potentially compromising system integrity.
All users in the Authenticated Users group on systems with vulnerable versions of Chocolatey Ruby are impacted by CVE-2022-45301.