HIGH
GHSA-x457-cw4h-hq5f
JSON gem has Improper Input Validation vulnerability
Quick fix
GHSA-x457-cw4h-hq5f — json: upgrade to the fixed version with the command below.
bundle update jsonDetails
The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-0269[ADVISORY]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82010[WEB]
- https://github.com/flori/json[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json/CVE-2013-0269.yml[WEB]
- https://groups.google.com/group/rubyonrails-security/msg/d8e0db6e08c81428?dmode=source&output=gplain[WEB]
- https://web.archive.org/web/20130228082541/http://www.securityfocus.com/bid/57899[WEB]
- https://web.archive.org/web/20160331131233/http://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed[WEB]
- https://web.archive.org/web/20160808163226/https://puppet.com/security/cve/cve-2013-0269[WEB]
- http://lists.apple.com/archives/security-announce/2013/Oct/msg00006.html[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00001.html[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00015.html[WEB]
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00034.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2013-0686.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2013-0701.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2013-1028.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2013-1147.html[WEB]
- http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released[WEB]
- http://www.openwall.com/lists/oss-security/2013/02/11/7[WEB]
- http://www.openwall.com/lists/oss-security/2013/02/11/8[WEB]
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2013&m=slackware-security.426862[WEB]
- http://www.ubuntu.com/usn/USN-1733-1[WEB]
- http://www.zweitag.de/en/blog/ruby-on-rails-vulnerable-to-mass-assignment-and-sql-injection[WEB]