Affected is the function self.meta_set of the file lib/dalli/protocol/meta/request_formatter.rb of the component Meta Protocol Handler. The manipulation leads to injection. The exploit has been disclosed to the public and may be used. The name of the patch is 48d594dae55934476fec61789e7a7c3700e0f50d. VDB-214026 is the identifier assigned to this vulnerability. Reference: https://github.com/petergoldstein/dalli/commit/48d594dae55934476fec61789e7a7c3700e0f50d https://github.com/petergoldstein/dalli/issues/932 https://github.com/petergoldstein/dalli/pull/933
Created rubygem-dalli tracking bugs for this issue: Affects: epel-all [bug 2147512] Affects: fedora-all [bug 2147511]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.