Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-32224

Опубликовано: 12 июл. 2022
Источник: redhat
CVSS3: 9
EPSS Низкий

Описание

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.

An insecure deserialization flaw was found in Active Record, which uses YAML.unsafe_load to convert the YAML data into Ruby objects. An attacker supplying crafted data to the database can perform remote code execution (RCE), resulting in complete system compromise.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2108997activerecord: Possible RCE escalation bug with Serialized Columns in Active Record

EPSS

Процентиль: 84%
0.02249
Низкий

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 3 лет назад

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.

CVSS3: 9.8
nvd
около 3 лет назад

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.

CVSS3: 9.8
debian
около 3 лет назад

A possible escalation to RCE vulnerability exists when using YAML seri ...

suse-cvrf
около 3 лет назад

Security update for rubygem-activerecord-5.2

CVSS3: 9.8
github
больше 3 лет назад

Active Record RCE bug with Serialized Columns

EPSS

Процентиль: 84%
0.02249
Низкий

9 Critical

CVSS3