Vulnerability Description
Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mruby | Mruby | < 3.2 |
Related Weaknesses (CWE)
References
- https://github.com/mruby/mruby/commit/a4d97934d51cb88954cc49161dc1d151f64afb6bPatchThird Party Advisory
- https://huntr.dev/bounties/23b6f0a9-64f5-421e-a55f-b5b7a671f301ExploitThird Party Advisory
- https://github.com/mruby/mruby/commit/a4d97934d51cb88954cc49161dc1d151f64afb6bPatchThird Party Advisory
- https://huntr.dev/bounties/23b6f0a9-64f5-421e-a55f-b5b7a671f301ExploitThird Party Advisory
FAQ
What is CVE-2022-1427?
CVE-2022-1427 is a vulnerability with a CVSS score of 7.8 (HIGH). Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.
How severe is CVE-2022-1427?
CVE-2022-1427 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1427?
Check the references section above for vendor advisories and patch information. Affected products include: Mruby Mruby.