PT-2023-20532 · Unknown · Geokit-Rails

Calum Hutton

·

Publicado

2023-10-05

·

Atualizado

2023-10-13

·

CVE-2023-26153

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions geokit-rails versions prior to 2.5.0
Description The issue is related to Command Injection due to unsafe deserialization of YAML within the geo location cookie. This can be exploited remotely via a malicious cookie value, allowing an attacker to execute commands on the host system.
Recommendations For versions prior to 2.5.0, update to version 2.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the geo location cookie to minimize the risk of exploitation.

Exploit

Correção

OS Command Injection

Deserialization of Untrusted Data

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26153
GHSA-7XVC-V44J-46FH

Produtos afetados

Geokit-Rails