JSON Project JSON 1.4.5 for Ruby

CPE Details

JSON Project JSON 1.4.5 for Ruby
1.4.5
2020-05-05
14h35 +00:00
2020-05-05
14h35 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:json_project:json:1.4.5:*:*:*:*:ruby:*:*

Informations

Vendor

json_project

Product

json

Version

1.4.5

Target Software

ruby

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2020-10663 2020-04-28 18h58 +00:00 The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.
7.5
Haute