Web Hack List

Collected research

Gem::SafeMarshal escape

Two escapes from Ruby's allow-list deserialiser: the permitted Date class calls the unrestricted loader on attacker data, and a length confusion in its instance-variable handling, where a particular string length makes the reader see zero, smuggles a crafted stream. Either regains unrestricted deserialisation and so a gadget chain to command execution.

Record

Researcher
Luke Jahnke
Published by
nastystereo.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Luke Jahnke, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .