{"id":"GHSA-g47j-3m2m-74qv","summary":"Duplicate Advisory: httparty has multipart/form-data request tampering vulnerability","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-5pq7-52mg-hr42. This link is maintained to preserve external references.\n\n### Original Description\nhttparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.","modified":"2026-02-03T03:16:26.383962Z","published":"2024-01-04T21:30:24Z","withdrawn":"2024-01-05T15:32:43Z","database_specific":{"cwe_ids":["CWE-472","CWE-668"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-05T15:32:43Z","nvd_published_at":"2024-01-04T21:15:10Z"},"references":[{"type":"WEB","url":"https://github.com/jnunemaker/httparty/security/advisories/GHSA-5pq7-52mg-hr42"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-22049"},{"type":"WEB","url":"https://github.com/jnunemaker/httparty/commit/cdb45a678c43e44570b4e73f84b1abeb5ec22b8e"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5pq7-52mg-hr42"},{"type":"WEB","url":"https://github.com/jnunemaker/httparty/blob/4416141d37fd71bdba4f37589ec265f55aa446ce/lib/httparty/request/body.rb#L43"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/01/msg00011.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00043.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4LDGAVPR4KB72V4GGQCWODEAI72QZI3V"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IOWECZPJY6JZIA5FSBJR77KCRDXWDZDA"},{"type":"WEB","url":"https://vulncheck.com/advisories/vc-advisory-GHSA-5pq7-52mg-hr42"}],"affected":[{"package":{"name":"httparty","ecosystem":"RubyGems","purl":"pkg:gem/httparty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.20.0"}]}],"versions":["0.1.0","0.1.1","0.1.2","0.1.3","0.1.5","0.1.6","0.1.7","0.1.8","0.10.0","0.10.1","0.10.2","0.11.0","0.12.0","0.13.0","0.13.1","0.13.2","0.13.3","0.13.4","0.13.5","0.13.6","0.13.7","0.14.0","0.15.0","0.15.1","0.15.2","0.15.3","0.15.4","0.15.5","0.15.6","0.15.7","0.16.0","0.16.1","0.16.2","0.16.3","0.16.4","0.17.0","0.17.1","0.17.3","0.18.0","0.18.1","0.19.0","0.19.1","0.2.0","0.2.1","0.2.10","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","0.2.8","0.2.9","0.20.0","0.3.0","0.3.1","0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5","0.5.0","0.5.1","0.5.2","0.6.0","0.6.1","0.7.0","0.7.2","0.7.3","0.7.4","0.7.6","0.7.7","0.7.8","0.8.0","0.8.1","0.8.2","0.8.3","0.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-g47j-3m2m-74qv/GHSA-g47j-3m2m-74qv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}