logo

Database

Lack of data validation In json

Description

JSON gem has Improper Input Validation vulnerability The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

References

1. https://exchange.xforce.ibmcloud.com/vulnerabilities/820102. https://github.com/rubysec/ruby-advisory-db/blob/master/gems/json/CVE-2013-0269.yml3. https://groups.google.com/group/rubyonrails-security/msg/d8e0db6e08c81428?dmode=source&output=gplain4. https://web.archive.org/web/20130228082541/http://www.securityfocus.com/bid/578995. https://web.archive.org/web/20160331131233/http://spreecommerce.com/blog/multiple-security-vulnerabilities-fixed6. https://web.archive.org/web/20160808163226/https://puppet.com/security/cve/cve-2013-02697. http://lists.apple.com/archives/security-announce/2013/Oct/msg00006.html8. http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00001.html9. http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00015.html10. http://lists.opensuse.org/opensuse-updates/2013-04/msg00034.html11. http://rhn.redhat.com/errata/RHSA-2013-0686.html12. http://rhn.redhat.com/errata/RHSA-2013-0701.html13. http://rhn.redhat.com/errata/RHSA-2013-1028.html14. http://rhn.redhat.com/errata/RHSA-2013-1147.html15. http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released16. http://www.openwall.com/lists/oss-security/2013/02/11/717. http://www.openwall.com/lists/oss-security/2013/02/11/818. http://www.slackware.com/security/viewer.php?l=slackware-security&y=2013&m=slackware-security.42686219. http://www.ubuntu.com/usn/USN-1733-120. http://www.zweitag.de/en/blog/ruby-on-rails-vulnerable-to-mass-assignment-and-sql-injection21. https://github.com/heroku/heroku-CVE-2013-0269
FLAT-RNWWS – Vulnerability | Fluid Attacks Database