PT-2023-20532 · Unknown · Geokit-Rails

Calum Hutton

·

Published

2023-10-05

·

Updated

2023-10-13

·

CVE-2023-26153

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions geokit-rails versions prior to 2.5.0
Description The issue is related to Command Injection due to unsafe deserialization of YAML within the geo location cookie. This can be exploited remotely via a malicious cookie value, allowing an attacker to execute commands on the host system.
Recommendations For versions prior to 2.5.0, update to version 2.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the geo location cookie to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Deserialization of Untrusted Data

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-26153
GHSA-7XVC-V44J-46FH

Affected Products

Geokit-Rails