Description
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2001-1243)
Contao Deserialization of Untrusted Data Vulnerability (CVE-2014-1860)
SharePoint CVE-2021-42294 Vulnerability (CVE-2021-42294)
phpMyAdmin Other Vulnerability (CVE-2005-0544)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-3508)