Vulnerabilities > CVE-2022-28481 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Csv-Safe Project Csv-Safe

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
csv-safe-project
CWE-1236

Summary

CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.