A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| activesupport(RubyGems) | 5.0.0 | 5.2.4.3 | N/A |
| activesupport(RubyGems) | 6.0.0 | 6.0.3.1 | N/A |
CVSS Metrics