Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-25739

Опубликовано: 23 сент. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 6.1

Описание

An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.

РелизСтатусПримечание
bionic

released

6.1.0-1+deb9u1build0.18.04.1
devel

DNE

esm-apps/bionic

released

6.1.0-1+deb9u1build0.18.04.1
esm-apps/focal

needed

esm-apps/jammy

not-affected

6.4.0-1
esm-apps/noble

not-affected

6.4.0-1
esm-apps/xenial

needed

esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needed
groovy

ignored

end of life

Показывать по

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
больше 5 лет назад

An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.

CVSS3: 6.1
debian
больше 5 лет назад

An issue was discovered in the gon gem before gon-6.4.0 for Ruby. Mult ...

CVSS3: 6.1
github
почти 5 лет назад

Gon gem lack of escaping certain input when outputting as JSON

4.3 Medium

CVSS2

6.1 Medium

CVSS3