Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-4410

Опубликовано: 20 фев. 2020
Источник: debian
EPSS Низкий

Описание

The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted string.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-bsonfixed1.10.0-2package
ruby-bsonfixed1.10.0-1+deb8u1jessiepackage

Примечания

  • "original" implementation of legal? using ^[0-9a-f]{24}$ regular expression

  • Fix: https://github.com/mongodb/mongo-ruby-driver/commit/bb544c2f6fd62940f04ddc1abeeaa3f23c1a9ade (1.x-stable)

  • http://sakurity.com/blog/2015/06/04/mongo_ruby_regexp.html

  • https://sources.debian.org/src/ruby-bson/1.10.0-1/lib/bson/types/object_id.rb/#L54

  • https://www.openwall.com/lists/oss-security/2015/06/06/1

EPSS

Процентиль: 84%
0.02283
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted string.

redhat
больше 10 лет назад

The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted string.

CVSS3: 7.5
nvd
почти 6 лет назад

The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted string.

CVSS3: 7.5
github
больше 5 лет назад

Moped Rubygem Data Injection Vulnerability

EPSS

Процентиль: 84%
0.02283
Низкий