Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19707
HistoryMay 16, 2019 - 3:22 a.m.

Deserialization Of Untrusted Data

2019-05-1603:22:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.022

Percentile

89.4%

Ruby is vulnerable to deserialization of untrusted data vulnerability. This attack appear to be exploitable via victim must run the gem owner command on a gem with a specially crafted YAML file which may leads to a code execution.