Логотип exploitDog
bind:CVE-2020-10663
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-10663

Количество 14

Количество 14

ubuntu логотип

CVE-2020-10663

больше 5 лет назад

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-10663

больше 5 лет назад

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2020-10663

больше 5 лет назад

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-10663

больше 5 лет назад

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9 ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-jphg-qwrw-7w9g

около 5 лет назад

Unsafe object creation in json RubyGem

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2020-5724

больше 5 лет назад

ELSA-2020-5724: pcs security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2020-02449

больше 5 лет назад

Уязвимость расширения JSON Gem интерпретатора языка программирования Ruby, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0586-1

больше 5 лет назад

Security update for ruby2.5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0995-1

больше 5 лет назад

Security update for ruby2.5

EPSS: Низкий
rocky логотип

RLSA-2021:2587

около 4 лет назад

Moderate: ruby:2.5 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2021-2587

около 4 лет назад

ELSA-2021-2587: ruby:2.5 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2021:2588

около 4 лет назад

Moderate: ruby:2.6 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2021-2588

около 4 лет назад

ELSA-2021-2588: ruby:2.6 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1570-1

больше 5 лет назад

Security update for ruby2.1

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-10663

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.

CVSS3: 7.5
4%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-10663

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.

CVSS3: 7.3
4%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-10663

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.

CVSS3: 7.5
4%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-10663

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9 ...

CVSS3: 7.5
4%
Низкий
больше 5 лет назад
github логотип
GHSA-jphg-qwrw-7w9g

Unsafe object creation in json RubyGem

CVSS3: 7.5
4%
Низкий
около 5 лет назад
oracle-oval логотип
ELSA-2020-5724

ELSA-2020-5724: pcs security update (IMPORTANT)

больше 5 лет назад
fstec логотип
BDU:2020-02449

Уязвимость расширения JSON Gem интерпретатора языка программирования Ruby, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
4%
Низкий
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0586-1

Security update for ruby2.5

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0995-1

Security update for ruby2.5

больше 5 лет назад
rocky логотип
RLSA-2021:2587

Moderate: ruby:2.5 security, bug fix, and enhancement update

около 4 лет назад
oracle-oval логотип
ELSA-2021-2587

ELSA-2021-2587: ruby:2.5 security, bug fix, and enhancement update (MODERATE)

около 4 лет назад
rocky логотип
RLSA-2021:2588

Moderate: ruby:2.6 security, bug fix, and enhancement update

около 4 лет назад
oracle-oval логотип
ELSA-2021-2588

ELSA-2021-2588: ruby:2.6 security, bug fix, and enhancement update (MODERATE)

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2020:1570-1

Security update for ruby2.1

больше 5 лет назад

Уязвимостей на страницу