ruby-jss is a provides native ruby access to the REST APIs of Jamf Pro, an enterprise/education tool for managing Apple devices, from jamf.com.
Affected versions of this package are vulnerable to Arbitrary Code Execution. The Pixar ruby-jss gem allows remote attackers to execute arbitrary code because of the Plist gem's documented behavior of using
Marshal.load during XML document processing.
ruby-jss to version 1.6.0 or higher.