|
|
| |
|
| |
ruby: denial of service
| Package(s): | ruby1.9.1 |
CVE #(s): | CVE-2013-0269
|
| Created: | February 21, 2013 |
Updated: | April 4, 2013 |
| Description: |
From the CVE entry:
The JSON gem 1.7.x before 1.7.7, 1.6.x before 1.6.8, and 1.5.x before 1.5.5 allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability." |
| Alerts: |
|
( Log in to post comments)
|
|
|