VYPR

Ruby Jss

by Pixar

CVEs (1)

  • CVE-2021-33575CriMay 25, 2021
    risk 0.64cvss 9.8epss 0.03

    The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of using Marshal.load during XML document processing.