v3.2.9
Security release. Fixes GHSA-6wmv-xq9m-fmp7, a memcached command injection through numeric arguments. Upgrading is recommended.
Security:
- Fix memcached command injection through the
incr/decrdefault with the meta protocol (GHSA-6wmv-xq9m-fmp7)- With
protocol: :meta, thedefaultargument ofincr/decrwas written into the command without conversion, so a String containing CRLF injected additional memcached commands (e.g.set,flush_all) on the connection. The default binary protocol is not affected defaultmust now be an Integer, or a String of decimal digits; anything else raisesArgumentErrorbefore a request is sent- As defense in depth, the meta
RequestFormatternow converts every numeric flag it writes (D,J,N,T) to an Integer - Thanks to oss-security-shop for the report
- With