Ruby/json/2.19.1
This is a JSON implementation as a Ruby extension in C.
https://rubygems.org/gems/json
Ruby
2 Security Vulnerabilities
Ruby JSON has a format string injection vulnerability
Impact
A format string injection vulnerability than that lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents.
This option isn't the default, if you didn't opt-in to use it, you are not impacted.
Patches
Patched in 2.19.2.
Workarounds
The issue can be avoided by not using the allow_duplicate_key: false parsing option.
Ruby JSON has a format string injection vulnerability
Impact
A format string injection vulnerability than that lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents.
This option isn't the default, if you didn't opt-in to use it, you are not impacted.
Patches
Patched in 2.19.2.
Workarounds
The issue can be avoided by not using the allow_duplicate_key: false parsing option.
128 Other Versions
| Version | License | Security | Released | |
|---|---|---|---|---|
| 1.4.3 | UNKNOWN | 4 | 2010-08-03 - 22:54 | almost 16 years |
| 1.4.2 | UNKNOWN | 4 | 2010-04-27 - 22:42 | about 16 years |
| 1.4.1 | UNKNOWN | 4 | 2010-04-25 - 13:47 | about 16 years |
| 1.4.0 | UNKNOWN | 4 | 2010-04-23 - 21:31 | about 16 years |
| 1.2.4 | UNKNOWN | 4 | 2010-04-08 - 07:52 | about 16 years |
| 1.2.3 | UNKNOWN | 4 | 2010-03-11 - 09:12 | about 16 years |
| 1.2.2 | UNKNOWN | 4 | 2010-02-28 - 17:17 | over 16 years |
| 1.2.1 | UNKNOWN | 4 | 2010-02-26 - 21:29 | over 16 years |
| 1.2.0 | UNKNOWN | 4 | 2009-11-08 - 04:16 | over 16 years |
| 1.1.9 | UNKNOWN | 4 | 2009-09-24 - 22:13 | over 16 years |
| 1.1.8 | UNKNOWN | 4 | 2009-09-24 - 22:13 | over 16 years |
| 1.1.7 | UNKNOWN | 4 | 2009-08-05 - 00:38 | almost 17 years |
| 1.1.6 | UNKNOWN | 4 | 2009-07-25 - 18:11 | almost 17 years |
| 1.1.5 | UNKNOWN | 4 | 2009-07-25 - 18:11 | almost 17 years |
| 1.1.4 | UNKNOWN | 4 | 2009-07-25 - 18:11 | almost 17 years |
| 1.1.3 | UNKNOWN | 4 | 2009-07-25 - 18:11 | almost 17 years |
| 1.1.2 | UNKNOWN | 4 | 2009-07-25 - 18:11 | almost 17 years |
| 1.1.1 | UNKNOWN | 4 | 2009-09-24 - 22:13 | over 16 years |
| 1.1.0 | UNKNOWN | 4 | 2009-09-24 - 22:13 | over 16 years |
| 1.0.4 | UNKNOWN | 5 | 2009-09-24 - 22:13 | over 16 years |
| 1.0.3 | UNKNOWN | 5 | 2009-09-24 - 22:13 | over 16 years |
| 1.0.2 | UNKNOWN | 5 | 2009-07-25 - 18:11 | almost 17 years |
| 1.0.1 | UNKNOWN | 5 | 2009-07-25 - 18:11 | almost 17 years |
| 1.0.0 | UNKNOWN | 5 | 2009-07-25 - 18:11 | almost 17 years |
| 0.4.3 | UNKNOWN | 5 | 2009-07-25 - 18:11 | almost 17 years |
| 0.4.2 | UNKNOWN | 5 | 2009-07-25 - 18:11 | almost 17 years |
| 0.4.1 | UNKNOWN | 5 | 2009-07-25 - 18:11 | almost 17 years |
| 0.4.0 | UNKNOWN | 5 | 2009-07-25 - 18:11 | almost 17 years |
