Collected research
Gem::SafeMarshal escape
Two escapes from Ruby's allow-list deserialiser: the permitted Date class calls the unrestricted loader on attacker data, and a length confusion in its instance-variable handling, where a particular string length makes the reader see zero, smuggles a crafted stream. Either regains unrestricted deserialisation and so a gadget chain to command execution.
Record
- Researcher
- Luke Jahnke
- Published by
- nastystereo.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Luke Jahnke, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .