CVE-2022-4064 is a problematic injection vulnerability in the Dalli Ruby gem, affecting versions up to 3.2.2. Specifically, it resides within the self.meta_set function of the Meta Protocol Handler, allowing remote attackers to inject data by manipulating the 'cas/ttl' argument. Despite a low CVSS score of 3.7, the attack complexity is high, and exploitability is difficult, with a potential impact of low integrity. While public exploit disclosure exists, there is no evidence of active exploitation, and it lacks exploit intelligence in common databases and community discussion. Upgrading to Dalli version 3.2.3 is recommended to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= -, < 3.2.3CPE matchmatch criteria | cpe:2.3:a:dalli_project:dalli:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.