Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0269

Опубликовано: 11 фев. 2013
Источник: redhat
CVSS2: 7.5

Описание

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

Отчет

Red Hat Satellite tools ship RubyGem Json 1.4.6 which is earlier than affected 1.5.5 version however, this version of RubyGem is not affected to the flaw. We may update RubyGem in a future release.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise MRG 2rubygem-jsonAffected
Red Hat JBoss SOA Platform 4jrubyWill not fix
Red Hat JBoss SOA Platform 5jrubyAffected
Red Hat Satellite 6satellite-toolsNot affected
Fuse ESB Enterprise 7.1.0FixedRHSA-2013:102809.07.2013
Red Hat JBoss Fuse 6.0FixedRHSA-2013:118529.08.2013
Red Hat JBoss SOA Platform 5.3FixedRHSA-2013:114708.08.2013
Red Hat Subscription Asset Manager 1.2candlepinFixedRHSA-2013:068626.03.2013
Red Hat Subscription Asset Manager 1.2katelloFixedRHSA-2013:068626.03.2013
Red Hat Subscription Asset Manager 1.2katello-configureFixedRHSA-2013:068626.03.2013

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=909029rubygem-json: Denial of Service and SQL Injection

7.5 High

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

nvd
больше 13 лет назад

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

debian
больше 13 лет назад

The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 ...

github
почти 9 лет назад

JSON gem has Improper Input Validation vulnerability

7.5 High

CVSS2