Information Exposure Affecting builder package, versions <2.1.2


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUBY-BUILDER-20001
  • published14 Jun 2007
  • disclosed14 Jun 2007
  • creditHagen Overdick

Introduced: 14 Jun 2007

CVE NOT AVAILABLE CWE-200  (opens in a new tab)

Overview

builder provides a number of builder objects that make creating structured data simple to do. Affected version of this gem mishandles reading tag names from XML data and then calls a method with the same name. With a specially crafted file, a context-dependent attacker can call private methods and manipulate data.

CVSS Scores

version 3.1