Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22758
HistoryMar 23, 2020 - 3:14 a.m.

Denial Of Service (DoS)

2020-03-2303:14:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

0.019 Low

EPSS

Percentile

88.5%

The JSON gem is vulnerable to denial of service. An attacker is able to create arbitrary objects in the target system using malicious JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects. This can potentially result in a denial of service condition. This vulnerability exists due to an incomplete fix for CVE-2013-0269.

References