Vulnerabilities (CVE)

Filtered by vendor Opensuse
Filtered by product Travel Support Program
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-46163 1 Opensuse 1 Travel Support Program 2024-11-21 N/A 7.5 HIGH
Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank account details, password Hash) can be extracted via Ransack query injection. Every deployment of travel-support-program below the patched version is affected. The travel-support-program uses the Ransack library to implement search functionality. In its default configuration, Ransack will allow for query conditions based on properties of associated database objects [1]. The `* ...

Show More