xsspresso
xsspresso
Tags/ YAML Deserialization

YAML Deserialization

1 writeup tagged with YAML Deserialization

WebEasyLinux

HTB — Precious

Pdfkit CVE-2022-25765 SSRF/command injection via URL parameter in PDF generation endpoint. Ruby bundler YAML deserialization for root.

#Pdfkit#CVE-2022-25765#YAML Deserialization
Jan 19, 2025HackTheBox