Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value.
Note:
An attacker can use this vulnerability to execute commands on the host system.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/26xxx/CVE-2023-26153.json",
"cwe_ids": [
"CWE-78"
],
"cna_assigner": "snyk",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "2.5.0"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"fixed": "2.5.0"
}
],
"source": "DESCRIPTION"
}
]
}