SB2020070952 - Input validation error in ruby (Alpine package)
Published: July 9, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2020-10663)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=9187c18b5ec330fb9b5af90d85672f02af3a15d5
- https://git.alpinelinux.org/aports/commit/?id=2831552db46aa5611d731c169b45810977d7b96a
- https://git.alpinelinux.org/aports/commit/?id=9d8c04b05e9bd2d754e1d7fafde8d286b14751d9
- https://git.alpinelinux.org/aports/commit/?id=d64618fe60af05a9e866c32d4bff6db761f2ea2b