CVE-2022-2714
CRITICALGitHub francoisjacquet/rosariosis <10.0 - Info Disclosure
Title source: llmDescription
Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0.
References (2)
Core 2
Core References
Permissions Required x_refsource_confirm
https://huntr.dev/bounties/430aedac-c7d9-4acb-9bab-bcc0595d9e95
Patch, Third Party Advisory x_refsource_misc
https://github.com/francoisjacquet/rosariosis/commit/4022954c3f41462bf6225c302a28b0429f6f4df3
Scores
CVSS v3
9.8
EPSS
0.0072
EPSS Percentile
48.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-130
Status
published
Products (2)
francoisjacquet/rosariosis
0 - 10.1Packagist
rosariosis/rosariosis
< 10.1
Published
Sep 06, 2022
Tracked Since
Feb 18, 2026