VDB
Sign up
HIGH7.5

GHSA-qh4w-7pw3-p4rp

BSON rubygem contains potential denial of service

Quick fix

GHSA-qh4w-7pw3-p4rp — bson: upgrade to the fixed version with the command below.

bundle update bson

Details

The `Moped::BSON::ObjecId.legal?` method in `mongodb/bson-ruby` before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-2015-4410.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/bson
Introduced in: 0Fixed in: 3.0.4
Fixbundle update bson

References