debian · CVE-2022-31033

Quick triage

Priority: not yet assigned Published: Updated: Thu, 23 Jul 2026 01:18:52 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2022-31033 not yet assigned priority: Debian including 1 source packages (ruby-mechanize), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 4, open 1.

Description:

The Mechanize library is used for automating interaction with websites. Mechanize automatically stores and sends cookies, follows redirects, and can follow links and submit forms. In versions prior to 2.8.5 the Authorization header is leaked after a redirect to a different port on the same site. Users are advised to upgrade to Mechanize v2.8.5 or later. There are no known workarounds for this issue.

cvelogic Threat Intelligence