VDB
Sign up
HIGH7.5

GHSA-34hf-g744-jw64

i18n Vulnerable to Denial of Service Attack

Quick fix

GHSA-34hf-g744-jw64 — i18n: upgrade to the fixed version with the command below.

bundle update i18n

Details

Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/i18n
Introduced in: 0Fixed in: 0.8.0
Fixbundle update i18n

References