GHSA-f93j-hmcr-jcwh

Suggest an improvement
Source
https://github.com/advisories/GHSA-f93j-hmcr-jcwh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-f93j-hmcr-jcwh/GHSA-f93j-hmcr-jcwh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f93j-hmcr-jcwh
Aliases
Published
2020-08-19T16:45:49Z
Modified
2024-02-16T08:10:02.211472Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Moped Rubygem Data Injection Vulnerability
Details

The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted string.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2020-08-14T16:47:12Z"
}
References

Affected packages

RubyGems / moped

Package

Name
moped
Purl
pkg:gem/moped

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.3

Affected versions

0.*

0.0.0.beta

1.*

1.0.0.alpha
1.0.0.beta
1.0.0.rc
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.1
1.2.2
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.5.0
1.5.1
1.5.2

RubyGems / moped

Package

Name
moped
Purl
pkg:gem/moped

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.0.5

Affected versions

2.*

2.0.0
2.0.1
2.0.2
2.0.3
2.0.4