Data Injection Affecting bson package, versions <1.12.3 >=2.0, <3.0.4
Threat Intelligence
EPSS
1.38% (87th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-BSON-20220
- published 3 Jun 2015
- disclosed 3 Jun 2015
- credit Unknown
Overview
bson
is a full featured BSON specification implementation in Ruby.
Affected versions of this gem allow an attacker to perform a BSON Injection. A flaw in the ObjectId
validation regular expression can enable attackers to inject arbitrary information into a given BSON object.
CVSS Scores
version 3.1