Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h2wm-p2vg-6pw4

Опубликовано: 09 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Kredis JSON Possible Deserialization of Untrusted Data Vulnerability

There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code. This vulnerability has been assigned the CVE identifier CVE-2023-27531.

'Not affected: None.' 'Versions Affected: All.' 'Fixed Versions: 1.3.0.1'

Impact Carefully crafted JSON data processed by Kredis may result in deserialization of untrusted data, potentially leading to deserialization of unexpected objects in the system.

Any applications using Kredis with JSON are affected.

Releases The fixed releases are available at the normal locations.

Workarounds There are no feasible workarounds for this issue.

Patches To aid users who aren’t able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.

  • 1-3-0-1-kredis.patch - Patch for 1.3.0 series

Credits Thank you ooooooo_k 7 for reporting this!

Пакеты

Наименование

kredis

rubygems
Затронутые версииВерсия исправления

< 1.3.0.1

1.3.0.1

EPSS

Процентиль: 26%
0.00091
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 года назад

There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code

EPSS

Процентиль: 26%
0.00091
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-502