Description
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
Remediation
References
Related Vulnerabilities
Internet Information Services Integer Overflow or Wraparound Vulnerability (CVE-2008-1446)
MySQL CVE-2013-0384 Vulnerability (CVE-2013-0384)
Django Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2022-23833)
PHP Missing Release of Resource after Effective Lifetime Vulnerability (CVE-2010-4657)