Количество 4
Количество 4
CVE-2020-25739
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.
CVE-2020-25739
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.
CVE-2020-25739
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. Mult ...
GHSA-78vq-9j56-wrfr
Gon gem lack of escaping certain input when outputting as JSON
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-25739 An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2020-25739 An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
CVE-2020-25739 An issue was discovered in the gon gem before gon-6.4.0 for Ruby. Mult ... | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
GHSA-78vq-9j56-wrfr Gon gem lack of escaping certain input when outputting as JSON | CVSS3: 6.1 | 1% Низкий | почти 5 лет назад |
Уязвимостей на страницу