HIGH
GHSA-3m6g-2423-7cp3
Ruby JSON has a format string injection vulnerability
Quick fix
GHSA-3m6g-2423-7cp3 — json: upgrade to the fixed version with the command below.
bundle update jsonDetails
### Impact
A format string injection vulnerability than that lead to denial of service attacks or information disclosure, when the `allow_duplicate_key: false` parsing option is used to parse user supplied documents.
This option isn't the default, if you didn't opt-in to use it, you are not impacted.
### Patches
Patched in `2.19.2`.
### Workarounds
The issue can be avoided by not using the `allow_duplicate_key: false` parsing option.
Are you affected?
Enter the version of the package you're using.