CVE-2023-26153
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Oct 6, 2023
Updated: Nov 7, 2023
CWE ID 78
CWE ID 502
Summary
CVE-2023-26153 is a command injection vulnerability affecting versions of the geokit-rails package prior to 2.5.0. The issue arises from unsafe deserialization of YAML contained within the 'geo_location' cookie. A malicious cookie value can be used to exploit this vulnerability remotely, potentially allowing an attacker to execute commands on the host system. This security flaw poses a significant threat and should be addressed promptly by updating to the latest version of geokit-rails.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share