[CVE-2023-27531] Possible Deserialization of Untrusted Data vulnerability in Kredis JSON
High
Vulnerability Details
I made a report and patch at https://hackerone.com/reports/1702859 .
https://discuss.rubyonrails.org/t/cve-2023-27531-possible-deserialization-of-untrusted-data-vulnerability-in-kredis-json/82467
> There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code. This vulnerability has been assigned the CVE identifier CVE-2023-27531.
## Impact
> Carefully crafted JSON data processed by Kredis may result in deserialization of untrusted data, potentially leading to deserialization of unexpected objects in the system.
Actions
View on HackerOneReport Stats
- Report ID: 2071554
- State: Closed
- Substate: resolved
- Upvotes: 14