Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-4410

Опубликовано: 20 фев. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted string.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:moped_project:moped:-:*:*:*:*:ruby:*:*
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*

EPSS

Процентиль: 84%
0.02283
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted string.

redhat
больше 10 лет назад

The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted string.

CVSS3: 7.5
debian
почти 6 лет назад

The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit ...

CVSS3: 7.5
github
больше 5 лет назад

Moped Rubygem Data Injection Vulnerability

EPSS

Процентиль: 84%
0.02283
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20