CVE-2021-33575

CRITICAL

Pixar ruby-jss < 1.6.0 - Remote Code Execution via Plist Marshal.load

Title source: llm
STIX 2.1

Description

The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of using Marshal.load during XML document processing.

Scores

CVSS v3 9.8
EPSS 0.0176
EPSS Percentile 82.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
pixar/ruby-jss < 1.6.0
rubygems/ruby-jss 0 - 1.6.0RubyGems
Published May 25, 2021
Tracked Since Feb 18, 2026