-
Notifications
You must be signed in to change notification settings - Fork 4
Dalli security warning #1038
Copy link
Copy link
Open
Labels
enhancementNew feature or requestNew feature or requestsecuritySecurity issue or CVE in dependencySecurity issue or CVE in dependency
Description
The log displays the following during startup:
SECURITY WARNING: Dalli is using Marshal for serialization. Marshal can execute arbitrary code during deserialization. If your memcached server could be compromised, consider using a safer serializer like JSON: Dalli::Client.new(servers, serializer: JSON)
If our memcached server is compromised, the whole server has been compromised. Dalli doesn't amplify the issues in this case.
To resolve, this warning should be squashed somehow.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestsecuritySecurity issue or CVE in dependencySecurity issue or CVE in dependency