{"id":"GHSA-7xvc-v44j-46fh","summary":"geokit-rails Command Injection vulnerability","details":"Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value.\n\n**Note:**\n\n An attacker can use this vulnerability to execute commands on the host system.","aliases":["CVE-2023-26153"],"modified":"2024-02-16T08:13:57.347777Z","published":"2023-10-06T06:30:16Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-10-06T18:45:58Z","nvd_published_at":"2023-10-06T05:15:52Z","cwe_ids":["CWE-502","CWE-77"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26153"},{"type":"WEB","url":"https://github.com/geokit/geokit-rails/commit/7ffc5813e57f6f417987043e1039925fd0865c43"},{"type":"WEB","url":"https://github.com/geokit/geokit-rails/commit/a93dfe49fb9aeae7164e2f8c4041450a04b5482f"},{"type":"WEB","url":"https://gist.github.com/CalumHutton/b7aa1c2e71c8d4386463ac14f686901d"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7xvc-v44j-46fh"},{"type":"PACKAGE","url":"https://github.com/geokit/geokit-rails"},{"type":"WEB","url":"https://github.com/geokit/geokit-rails/blob/master/lib/geokit-rails/ip_geocode_lookup.rb#L37"},{"type":"WEB","url":"https://github.com/geokit/geokit-rails/blob/master/lib/geokit-rails/ip_geocode_lookup.rb%23L37"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/geokit-rails/CVE-2023-26153.yml"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-RUBY-GEOKITRAILS-5920323"}],"affected":[{"package":{"name":"geokit-rails","ecosystem":"RubyGems","purl":"pkg:gem/geokit-rails"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.0"}]}],"versions":["1.1.4","2.0.0","2.0.0.rc1","2.0.1","2.1.0","2.2.0","2.3.0","2.3.1","2.3.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-7xvc-v44j-46fh/GHSA-7xvc-v44j-46fh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}