GHSA-jphg-qwrw-7w9g

Suggest an improvement
Source
https://github.com/advisories/GHSA-jphg-qwrw-7w9g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/07/GHSA-jphg-qwrw-7w9g/GHSA-jphg-qwrw-7w9g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jphg-qwrw-7w9g
Aliases
Published
2020-07-27T18:08:21Z
Modified
2024-03-08T05:19:30.353798Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Unsafe object creation in json RubyGem
Details

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269/GHSA-x457-cw4h-hq5f, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.

Database specific
{
    "nvd_published_at": "2020-04-28T21:15:00Z",
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2020-07-27T18:07:46Z"
}
References

Affected packages

RubyGems / json

Package

Name
json
Purl
pkg:gem/json

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.0

Affected versions

0.*

0.4.0
0.4.1
0.4.2
0.4.3

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.6.0
1.6.0.1
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.8.5
1.8.6

2.*

2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.2.0