GHSA-qh4w-7pw3-p4rp

Suggest an improvement
Source
https://github.com/advisories/GHSA-qh4w-7pw3-p4rp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-qh4w-7pw3-p4rp/GHSA-qh4w-7pw3-p4rp.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-qh4w-7pw3-p4rp
Aliases
  • CVE-2015-4411
Published
2020-04-29T15:34:50Z
Modified
2023-11-01T04:46:08.300853Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
BSON rubygem contains potential denial of service
Details

The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-2015-4410.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-400"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2020-04-23T20:14:17Z"
}
References

Affected packages

RubyGems / bson

Package

Name
bson
Purl
pkg:gem/bson

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.4

Affected versions

0.*

0.20
0.20.1

1.*

1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.rc0
1.2.rc1
1.2.rc2
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0.rc0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0.rc0
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.4
1.7.0.rc0
1.7.0
1.7.1
1.8.0
1.8.1.rc0
1.8.1.rc1
1.8.1
1.8.2
1.8.3.rc0
1.8.3.rc1
1.8.3
1.8.4.rc0
1.8.4
1.8.5
1.8.6
1.9.0
1.9.1.rc0
1.9.1
1.9.2
1.10.0.rc0
1.10.0.rc1
1.10.0
1.10.1
1.10.2
1.11.1
1.12.0.rc0
1.12.0.rc1
1.12.0.rc2
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.12.5

2.*

2.0.0.alpha
2.0.0.beta
2.0.0.rc
2.0.0.rc1
2.0.0.rc2
2.0.0.rc3
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.3.0

3.*

3.0.0
3.0.1
3.0.2
3.0.3