The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
28 Mar 2023, 18:06
Type | Values Removed | Values Added |
---|---|---|
CPE |
18 Apr 2022, 15:21
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:* | |
References | (MLIST) https://lists.apache.org/thread.html/r37c0e1807da7ff2bdd028bbe296465a6bbb99e2320dbe661d5d8b33b@%3Cissues.zookeeper.apache.org%3E - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r3b04f4e99a19613f88ae088aa18cd271231a3c79dfff8f5efa8cda61@%3Cissues.zookeeper.apache.org%3E - Mailing List, Third Party Advisory |
22 Sep 2021, 14:22
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:apple:macos:11.0.1:*:*:*:*:*:*:* |
Information
Published : 2020-04-28 21:15
Updated : 2024-02-04 21:00
NVD link : CVE-2020-10663
Mitre link : CVE-2020-10663
CVE.ORG link : CVE-2020-10663
JSON object : View
Products Affected
json_project
- json
apple
- macos
debian
- debian_linux
fedoraproject
- fedora
opensuse
- leap
ruby-lang
- ruby
CWE
CWE-20
Improper Input Validation