Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3716-1 | ruby-httparty security update |
Debian DLA |
DLA-3900-1 | ruby-httparty security update |
EUVD |
EUVD-2023-0342 | httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written. |
Github GHSA |
GHSA-5pq7-52mg-hr42 | httparty has multipart/form-data request tampering vulnerability |
Wed, 07 Jan 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Debian
Debian debian Linux Fedoraproject Fedoraproject fedora Jnunemaker Jnunemaker httparty |
|
| Weaknesses | CWE-668 | |
| CPEs | cpe:2.3:a:jnunemaker:httparty:*:*:*:*:*:ruby:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
|
| Vendors & Products |
Debian
Debian debian Linux Fedoraproject Fedoraproject fedora Jnunemaker Jnunemaker httparty |
Tue, 03 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written. | httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written. |
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-29T01:18:47.199Z
Reserved: 2024-01-04T18:44:53.108Z
Link: CVE-2024-22049
Updated: 2024-09-28T12:03:40.887Z
Status : Analyzed
Published: 2024-01-04T21:15:10.013
Modified: 2026-01-07T19:49:03.943
Link: CVE-2024-22049
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA