Sploitus

CVE-2022-28739

No indexed exploits for CVE-2022-28739 yet

There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f.

Ruby-lang Ruby
< 2.6.10, 2.7.6, 3.0.4, 3.1.2
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
4.3% (90th percentile)
Weakness
CWE-125
NVD status
Modified
Published
2022-05-09
CVE-2022-28739 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-28739 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-28739 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.