The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2190-1 | ruby-json security update |
Debian DLA |
DLA-2192-1 | ruby2.1 security update |
Debian DSA |
DSA-4721-1 | ruby2.5 security update |
EUVD |
EUVD-2020-0563 | The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent. |
Github GHSA |
GHSA-jphg-qwrw-7w9g | Unsafe object creation in json RubyGem |
Ubuntu USN |
USN-4882-1 | Ruby vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:06:10.608Z
Reserved: 2020-03-18T00:00:00
Link: CVE-2020-10663
No data.
Status : Modified
Published: 2020-04-28T21:15:11.667
Modified: 2024-11-21T04:55:47.670
Link: CVE-2020-10663
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN