QID 995539
Date Published: 2023-10-09
QID 995539: Rubygems (Rubygems) Security Update for geokit-rails (GHSA-7xvc-v44j-46fh)
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-7xvc-v44j-46fh for updates and patch information.
Vendor References
- GHSA-7xvc-v44j-46fh -
github.com/advisories/GHSA-7xvc-v44j-46fh
CVEs related to QID 995539
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7xvc-v44j-46fh | geokit-rails |
|