v4.3.4
Security release. Fixes GHSA-6wmv-xq9m-fmp7, a memcached command injection through numeric arguments. Upgrading is recommended.
Security:
- Fix memcached command injection through numeric arguments with the meta protocol (GHSA-6wmv-xq9m-fmp7)
- With
protocol: :meta, thedefaultargument ofincr/decr, andfetch_with_lock'slock_ttlandrecache_threshold, were written into the command without conversion, so a String containing CRLF injected additional memcached commands (e.g.set,flush_all) on the connection. The default binary protocol is not affected - These arguments must now be Integers, or Strings of decimal digits; anything else raises
ArgumentErrorbefore a request is sent - As defense in depth, the meta
RequestFormatternow converts every numeric flag it writes (D,J,N,R,T) to an Integer - Thanks to oss-security-shop for the report
- With