[CVE-2023-27531] Possible Deserialization of Untrusted Data vulnerability in Kredis JSON

Disclosed: 2023-08-15 20:21:08 By ooooooo_q To ibb
High
Vulnerability Details
I made a report and patch at https://hackerone.com/reports/1702859 . https://discuss.rubyonrails.org/t/cve-2023-27531-possible-deserialization-of-untrusted-data-vulnerability-in-kredis-json/82467 > There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code. This vulnerability has been assigned the CVE identifier CVE-2023-27531. ## Impact > Carefully crafted JSON data processed by Kredis may result in deserialization of untrusted data, potentially leading to deserialization of unexpected objects in the system.
Actions
View on HackerOne
Report Stats
  • Report ID: 2071554
  • State: Closed
  • Substate: resolved
  • Upvotes: 14
Share this report