CVE-2023-26153

Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. **Note:** An attacker can use this vulnerability to execute commands on the host system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:geokit:geokit-rails:*:*:*:*:*:rails:*:*

History

21 Nov 2024, 07:50

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-06 05:15

Updated : 2024-11-21 07:50


NVD link : CVE-2023-26153

Mitre link : CVE-2023-26153

CVE.ORG link : CVE-2023-26153


JSON object : View

Products Affected

geokit

  • geokit-rails
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-502

Deserialization of Untrusted Data