Remote code execution in ruby-jss
Published: October 06, 2021
SECURITY IDENTIFIERS
- CVE: CVE-2021-33575 (NVD)
- GHSA: GHSA-vmfh-c547-v45h
GEM
SEVERITY
CVSS v3.x: 9.8 (Critical)
PATCHED VERSIONS
>= 1.6.0
DESCRIPTION
The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of using Marshal.load during XML document processing.
