CVE-2022-39281
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/10/2022
Last modified:
11/10/2022
Description
fat_free_crm is a an open source, Ruby on Rails customer relationship management platform (CRM). In versions prior to 0.20.1 an authenticated user can perform a remote Denial of Service attack against Fat Free CRM via bucket access. The vulnerability has been patched in commit `c85a254` and will be available in release `0.20.1`. Users are advised to upgrade or to manually apply patch `c85a254`. There are no known workarounds for this issue.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:fatfreecrm:fatfreecrm:*:*:*:*:*:ruby:*:* | 0.20.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



