Описание
redis-store deserializes untrusted data
Redis-store prior to 1.4.0 allows unsafe objects to be loaded from redis
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000248
- https://github.com/redis-store/redis-store/commit/ce13252c26fcc40ed4935c9abfeb0ee0761e5704
- https://github.com/redis-store/redis-store/commit/e0c1398d54a9661c8c70267c3a925ba6b192142e
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/redis-store/CVE-2017-1000248.yml
Пакеты
Наименование
redis-store
rubygems
Затронутые версииВерсия исправления
< 1.4.0
1.4.0
Связанные уязвимости
CVSS3: 9.8
ubuntu
около 8 лет назад
Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis
CVSS3: 9.8
nvd
около 8 лет назад
Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis
CVSS3: 9.8
debian
около 8 лет назад
Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis