CVE-2021-33575: Remote code execution in ruby-jss

Severity: Critical

CVSS Score: 9.8

The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of using Marshal.load during XML document processing.