Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
- Snyk ID SNYK-RUBY-GEOKITRAILS-5920323
- published 5 Oct 2023
- disclosed 26 Sep 2023
- credit Calum Hutton
How to fix?
geokit-rails to version 2.5.0 or higher.
Affected versions of this package are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value.
An attacker can use this vulnerability to execute commands on the host system.