The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.
References
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Information
Published : 2020-04-28 21:15
Updated : 2021-09-22 14:22
NVD link : CVE-2020-10663
Mitre link : CVE-2020-10663
JSON object : View
Products Affected
debian
- debian_linux
fedoraproject
- fedora
json_project
- json
opensuse
- leap
apple
- macos
ruby-lang
- ruby
CWE
CWE-20
Improper Input Validation
