Medium severity5.3GHSA Advisory· Published Jan 9, 2025· Updated Jun 17, 2026
CVE-2023-27531
CVE-2023-27531
Description
There is a deserialization of untrusted data vulnerability in the Kredis JSON deserialization code
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kredisRubyGems | < 1.3.0.1 | 1.3.0.1 |
Affected products
2- Range: < 1.3.0.1
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-h2wm-p2vg-6pw4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-27531ghsaADVISORY
- discuss.rubyonrails.org/t/cve-2023-27531-possible-deserialization-of-untrusted-data-vulnerability-in-kredis-json/82467nvdWEB
- discuss.rubyonrails.org/t/cve-2023-27531-possible-deserialization-of-untrusted-data-vulnerability-in-kredis-json/82467ghsaWEB
- github.com/rails/kredis/commit/d576b7ae5c8d3d74eeb4bd84cad0aa64ffc299faghsaWEB
- github.com/rails/kredis/releases/tag/v1.3.0.1ghsaWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/kredis/CVE-2023-27531.ymlghsaWEB
News mentions
0No linked articles in our index yet.