Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3m6g-2423-7cp3

Опубликовано: 19 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.3

Описание

Ruby JSON has a format string injection vulnerability

Impact

A format string injection vulnerability than that lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents.

This option isn't the default, if you didn't opt-in to use it, you are not impacted.

Patches

Patched in 2.19.2.

Workarounds

The issue can be avoided by not using the allow_duplicate_key: false parsing option.

Пакеты

Наименование

json

rubygems
Затронутые версииВерсия исправления

>= 2.18.0, < 2.19.2

2.19.2

Наименование

json

rubygems
Затронутые версииВерсия исправления

>= 2.16.0, < 2.17.1.2

2.17.1.2

Наименование

json

rubygems
Затронутые версииВерсия исправления

>= 2.14.0, < 2.15.2.1

2.15.2.1

EPSS

Процентиль: 54%
0.00838
Низкий

8.3 High

CVSS4

Дефекты

CWE-134

Связанные уязвимости

CVSS3: 9.1
ubuntu
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

CVSS3: 9.1
redhat
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

CVSS3: 9.1
nvd
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

CVSS3: 9.1
debian
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to be ...

rocky
около 2 месяцев назад

Important: ruby4.0 security update

EPSS

Процентиль: 54%
0.00838
Низкий

8.3 High

CVSS4

Дефекты

CWE-134