Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x457-cw4h-hq5f

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

JSON gem has Improper Input Validation vulnerability

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

Пакеты

Наименование

json

rubygems
Затронутые версииВерсия исправления

< 1.5.5

1.5.5

Наименование

json

rubygems
Затронутые версииВерсия исправления

>= 1.6.0, < 1.6.8

1.6.8

Наименование

json

rubygems
Затронутые версииВерсия исправления

>= 1.7.0, < 1.7.7

1.7.7

EPSS

Процентиль: 95%
0.17317
Средний

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 13 лет назад

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

redhat
почти 13 лет назад

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

nvd
почти 13 лет назад

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

debian
почти 13 лет назад

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 ...

EPSS

Процентиль: 95%
0.17317
Средний

Дефекты

CWE-20