Web Hack List

Other nomination

Gem::SafeMarshal escape

Two escapes from Ruby's allow-list deserialiser: the permitted Date class calls the unrestricted loader on attacker data, and a length confusion in its instance-variable handling, where a particular string length makes the reader see zero, smuggles a crafted stream. Either regains unrestricted deserialisation and so a gadget chain to command execution.

Record

Researcher
Luke Jahnke

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Luke Jahnke, first published at the original source. Preserved copies are kept so the citation survives its host.