RubySec

Providing security resources for the Ruby community

CVE-2022-31115 (opensearch-ruby): Unsafe YAML deserialization in opensearch-ruby

ADVISORIES

GEM

opensearch-ruby

SEVERITY

CVSS v3.x: 8.8 (High)

PATCHED VERSIONS

  • >= 2.0.2

DESCRIPTION

Impact

A YAML deserialization in opensearch-ruby 2.0.0 can lead to unsafe deserialization using YAML.load if the response is of type YAML.

Patches

The problem has been patched in opensearch-ruby gem version 2.0.2.

Workarounds

No viable workaround. Please upgrade to 2.0.2

RELATED