Lucene search

K
osvGoogleOSV:GHSA-MQWR-4QF2-2HCV
HistoryMay 13, 2022 - 1:38 a.m.

RubyGems vulnerable to Deserialization of Untrusted Data

2022-05-1301:38:26
Google
osv.dev
11

0.135 Low

EPSS

Percentile

95.6%

RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution. The issue has been patched in 2.6.14.