VDB
Sign up
CRITICAL9.8

GHSA-h6rj-8r3c-9gpj

bson is vulnerable to denial of service due to incorrect regex validation

Quick fix

GHSA-h6rj-8r3c-9gpj — bson: upgrade to the fixed version with the command below.

bundle update bson

Details

BSON injection vulnerability in the legal function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/bson
Introduced in: 0Fixed in: 1.12.3
Fixbundle update bson
RubyGems/bson
Introduced in: 2.0Fixed in: 3.0.4
Fixbundle update bson

References