gon Project gon 2.0.0 for Ruby

CPE Details

gon Project gon 2.0.0 for Ruby
2.0.0
2020-09-23
19h26 +00:00
2021-03-04
16h37 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gon_project:gon:2.0.0:*:*:*:*:ruby:*:*

Informations

Vendor

gon_project

Product

gon

Version

2.0.0

Target Software

ruby

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-25739 2020-09-23 11h53 +00:00 An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.
6.1
Medium