Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46064
HistoryMar 28, 2024 - 10:48 a.m.

Remote Code Execution

2024-03-2810:48:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
remote code execution
rdoc
software vulnerability
unrestricted class restoration
code injection
yaml file parsing

CVSS3

4.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

AI Score

7.7

Confidence

High

rdoc is vulnerable to Remote Code Execution. The vulnerability is due to unrestricted class restoration when parsing .rdoc_options as a YAML file, allowing for object injection and code injection.

CVSS3

4.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

AI Score

7.7

Confidence

High