|
| 1 | +--- |
| 2 | +layout: advisory |
| 3 | +title: 'GHSA-wr87-m4jw-29x5 (dalli): Per-request raw and the JSON serializer don''t |
| 4 | + prevent unsafe deserialization' |
| 5 | +comments: false |
| 6 | +categories: |
| 7 | +- dalli |
| 8 | +advisory: |
| 9 | + gem: dalli |
| 10 | + ghsa: wr87-m4jw-29x5 |
| 11 | + url: https://github.com/petergoldstein/dalli/security/advisories/GHSA-wr87-m4jw-29x5 |
| 12 | + title: Per-request raw and the JSON serializer don't prevent unsafe deserialization |
| 13 | + date: 2026-10-05 |
| 14 | + description: |- |
| 15 | + 1. Per-request `raw: true` was ignored by some read methods, which still |
| 16 | + ran the configured serializer's `load` (Marshal by default) on values |
| 17 | + whose flags say they're serialized: in 5.1 and 5.2, `get_multi`, |
| 18 | + `get_multi_cas`, `get_multi_with_metadata`, `get_cas` and |
| 19 | + `get_with_metadata`; in 5.0, `get_with_metadata`; in 4.x, `get`, |
| 20 | + `gat` and `fetch` with the binary protocol, and `get_with_metadata`; |
| 21 | + in 3.x, `get`, `gat` and `fetch`. |
| 22 | + 2. `serializer: JSON` resolves to `JSON.load`. With the json gem before |
| 23 | + 3.0, `JSON.load` honors `json_class` when the json additions are |
| 24 | + loaded, so a crafted value can instantiate classes that define |
| 25 | + `json_create`. |
| 26 | +
|
| 27 | + Exploiting either requires write access to the memcached instance and |
| 28 | + an application relying on per-request `raw: true` or `serializer: JSON` |
| 29 | + to avoid unsafe deserialization. Patched versions add |
| 30 | + `Dalli::JSONSerializer`, which reads with `JSON.parse`. |
| 31 | +
|
| 32 | + The first fix (5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12) was incomplete: |
| 33 | + on 5.0, 4.3 and 3.2, `cas` and `cas!` (and `fetch_with_lock` on 5.0, |
| 34 | + and on 4.3 with the meta protocol) still deserialized values read with |
| 35 | + `raw: true`, and on every line but 3.2 a raw read still honored flags a |
| 36 | + reply carried unasked. Both are fixed in 5.2.2, 5.1.4, 5.0.10, 4.3.7 |
| 37 | + and 3.2.13. |
| 38 | +
|
| 39 | + ### Workarounds |
| 40 | +
|
| 41 | + Use a serializer that only parses data, such as one wrapping |
| 42 | + `JSON.parse`, instead of `serializer: JSON`. |
| 43 | + patched_versions: |
| 44 | + - "~> 3.2.13" |
| 45 | + - "~> 4.3.7" |
| 46 | + - "~> 5.0.10" |
| 47 | + - "~> 5.1.4" |
| 48 | + - ">= 5.2.2" |
| 49 | + related: |
| 50 | + url: |
| 51 | + - https://github.com/petergoldstein/dalli/security/advisories/GHSA-wr87-m4jw-29x5 |
| 52 | + - https://github.com/petergoldstein/dalli/commit/8529428 |
| 53 | + - https://rubygems.org/gems/dalli/versions/5.2.2 |
| 54 | + - https://github.com/petergoldstein/dalli/releases/tag/v5.2.2 |
| 55 | + - https://rubygems.org/gems/dalli/versions/5.1.4 |
| 56 | + - https://github.com/petergoldstein/dalli/releases/tag/v5.1.4 |
| 57 | + - https://rubygems.org/gems/dalli/versions/5.0.10 |
| 58 | + - https://github.com/petergoldstein/dalli/releases/tag/v5.0.10 |
| 59 | + - https://rubygems.org/gems/dalli/versions/4.3.7 |
| 60 | + - https://github.com/petergoldstein/dalli/releases/tag/v4.3.7 |
| 61 | + - https://rubygems.org/gems/dalli/versions/3.2.13 |
| 62 | + - https://github.com/petergoldstein/dalli/releases/tag/v3.2.13 |
| 63 | + - https://rubygems.org/gems/dalli/versions/5.2.1 |
| 64 | + - https://github.com/petergoldstein/dalli/releases/tag/v5.2.1 |
| 65 | + - https://rubygems.org/gems/dalli/versions/5.1.3 |
| 66 | + - https://github.com/petergoldstein/dalli/releases/tag/v5.1.3 |
| 67 | + - https://rubygems.org/gems/dalli/versions/5.0.9 |
| 68 | + - https://github.com/petergoldstein/dalli/releases/tag/v5.0.9 |
| 69 | + - https://rubygems.org/gems/dalli/versions/4.3.6 |
| 70 | + - https://github.com/petergoldstein/dalli/releases/tag/v4.3.6 |
| 71 | + - https://rubygems.org/gems/dalli/versions/3.2.12 |
| 72 | + - https://github.com/petergoldstein/dalli/releases/tag/v3.2.12 |
| 73 | + notes: | |
| 74 | + - No CVE in GHSA. |
| 75 | + - "A CVE has been requested through GitHub but not yet |
| 76 | + assigned, so the entry has no cve: field." |
| 77 | + - No CVSS score in GHSA; GitHub severity is low. |
| 78 | +--- |
0 commit comments