rubygem-moped: Denial of Service with crafted ObjectId string
Published Feb 20, 2020
7.5
HIGHCVSS 3.1
EPSS 5.66%
Description
The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted string.
Affected products
No data.
Configuration 1
- n/a
Configuration 2
- 21
- 22
No data.
Red Hat OpenShift Enterprise 2
ruby193-rubygem-moped
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Enterprise 2 | ruby193-rubygem-moped | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of rubygem-moped as shipped with Red Hat OpenShift Enterprise 2.x. Red Hat Product Security has rated this issue as having Low security impact on Red Hat OpenShift Enterprise 2. Additionally access to the component using rubygem-moped is restricted, only trusted users and systems can send messages, thus no trust boundary violation occurs and this issue can not easily be used to create an exploitable security vulnerability on Red Hat OpenShift Enterprise 2.
References (18)
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161964.html x_refsource_MISCMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161987.html x_refsource_MISCMailing ListThird Party Advisory
- http://sakurity.com/blog/2015/06/04/mongo_ruby_regexp.html
- http://www.openwall.com/lists/oss-security/2015/06/06/3 x_refsource_MISCMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/75045 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2015-4410 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1229757 x_refsource_MISCIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0619 Advisory
- https://github.com/advisories/GHSA-f93j-hmcr-jcwh Advisory
- https://github.com/mongoid/moped/commit/dd5a7c14b5d2e466f7875d079af71ad19774609b#diff-3b93602f64c2fe46d38efd9f73ef5358R24 x_refsource_MISCExploit
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/moped/CVE-2015-4410.yml
- https://homakov.blogspot.ru/2012/05/saferweb-injects-in-various-ruby.html x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-4410
- https://sakurity.com/blog/2015/06/04/mongo_ruby_regexp.html x_refsource_MISCExploitThird Party Advisory
- https://seclists.org/oss-sec/2015/q2/653 x_refsource_MISCMailing ListThird Party Advisory
- https://web.archive.org/web/20200228085849/http://www.securityfocus.com/bid/75045
- https://www.cve.org/CVERecord?id=CVE-2015-4410
- https://www.securityfocus.com/bid/75045 x_refsource_MISCThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.