CVE Database
/

CVE-2024-22049

Back to search

CVE-2024-22049

Published: Jan 4, 2024

Modified: Nov 29, 2025

PUBLISHED

Description

httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.

VendorProductVersions

Unknown

httparty

affected
0 - <= 0.20.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now