Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-0269

Опубликовано: 13 фев. 2013
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:rubygems:json_gem:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.6.5:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.6.6:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.6.7:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.7.2:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.7.3:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.7.4:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.7.5:*:*:*:*:*:*:*
cpe:2.3:a:rubygems:json_gem:1.7.6:*:*:*:*:*:*:*

EPSS

Процентиль: 96%
0.13911
Средний

7.5 High

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 13 лет назад

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

redhat
больше 13 лет назад

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

debian
больше 13 лет назад

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 ...

github
почти 9 лет назад

JSON gem has Improper Input Validation vulnerability

EPSS

Процентиль: 96%
0.13911
Средний

7.5 High

CVSS2

Дефекты

CWE-20