CVE Vulnerabilities

CVE-2021-33575

Published: May 25, 2021 | Modified: Jun 01, 2021
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gems documented behavior of using Marshal.load during XML document processing.

Affected Software

Name Vendor Start Version End Version
Ruby-jss Pixar * 1.6.0 (excluding)

References