Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-4411

Опубликовано: 20 фев. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-2015-4410.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mongodb:bson:*:*:*:*:*:ruby:*:*
Версия до 3.0.4 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.0308
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-2015-4410.

redhat
больше 10 лет назад

The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-2015-4410.

CVSS3: 7.5
debian
почти 6 лет назад

The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0 ...

CVSS3: 7.5
github
почти 6 лет назад

BSON rubygem contains potential denial of service

EPSS

Процентиль: 86%
0.0308
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400