BSON rubygem contains potential denial of service
High severity
GitHub Reviewed
Published
Apr 29, 2020
to the GitHub Advisory Database
•
Updated Aug 25, 2023
Description
Reviewed
Apr 23, 2020
Published to the GitHub Advisory Database
Apr 29, 2020
Last updated
Aug 25, 2023
The
Moped::BSON::ObjecId.legal?
method inmongodb/bson-ruby
before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-2015-4410.References