redis-store deserializes untrusted data
Critical severity
GitHub Reviewed
Published
Dec 6, 2017
to the GitHub Advisory Database
•
Updated Aug 28, 2023
Description
Published to the GitHub Advisory Database
Dec 6, 2017
Reviewed
Jun 16, 2020
Last updated
Aug 28, 2023
Redis-store prior to 1.4.0 allows unsafe objects to be loaded from redis
References