Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7xvc-v44j-46fh

Опубликовано: 06 окт. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

geokit-rails Command Injection vulnerability

Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value.

Note:

An attacker can use this vulnerability to execute commands on the host system.

Пакеты

Наименование

geokit-rails

rubygems
Затронутые версииВерсия исправления

< 2.5.0

2.5.0

EPSS

Процентиль: 50%
0.00265
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502
CWE-77

Связанные уязвимости

CVSS3: 8.3
nvd
больше 2 лет назад

Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. **Note:** An attacker can use this vulnerability to execute commands on the host system.

EPSS

Процентиль: 50%
0.00265
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502
CWE-77