RubySec

Providing security resources for the Ruby community

CVE-2021-33575 (ruby-jss): Remote code execution in ruby-jss

ADVISORIES

GEM

ruby-jss

SEVERITY

CVSS v3.x: 9.8 (Critical)

PATCHED VERSIONS

  • >= 1.6.0

DESCRIPTION

The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem’s documented behavior of using Marshal.load during XML document processing.