Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wg9m-gw3h-hg83

Опубликовано: 16 июл. 2019
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

field_test gem contains injection vulnerability

The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS).

Пакеты

Наименование

field_test

rubygems
Затронутые версииВерсия исправления

= 0.3.0

0.3.1

EPSS

Процентиль: 49%
0.00257
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 5.3
nvd
больше 6 лет назад

The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS).

EPSS

Процентиль: 49%
0.00257
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-74