← Back

CVE-2020-10663

nvd nist
Published: Apr 28, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.

Affected (7)

Products: Json Project: Json · Fedoraproject: Fedora · Opensuse: Leap · +2 more
Show all products
1 product
Json
1 product
Fedora
1 product
Leap
1 product
Debian Linux
1 product
Macos
Configuration A
1 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Up to 2.2.0
Running on/withPlatform Versions
Ruby Lang
Ruby
From 2.4.0 to 2.4.9
Ruby Lang
Ruby
From 2.5.0 to 2.5.7
Ruby Lang
Ruby
From 2.6.0 to 2.6.5
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0.1

References (38)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.