VDB
Sign up
HIGH

GHSA-3m6g-2423-7cp3

Ruby JSON has a format string injection vulnerability

Quick fix

GHSA-3m6g-2423-7cp3 — json: upgrade to the fixed version with the command below.

bundle update json

Details

### Impact

A format string injection vulnerability than that lead to denial of service attacks or information disclosure, when the `allow_duplicate_key: false` parsing option is used to parse user supplied documents.

This option isn't the default, if you didn't opt-in to use it, you are not impacted.

### Patches

Patched in `2.19.2`.

### Workarounds

The issue can be avoided by not using the `allow_duplicate_key: false` parsing option.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/json
Introduced in: 2.18.0Fixed in: 2.19.2
Fixbundle update json
RubyGems/json
Introduced in: 2.16.0Fixed in: 2.17.1.2
Fixbundle update json
RubyGems/json
Introduced in: 2.14.0Fixed in: 2.15.2.1
Fixbundle update json

References