CVE-2015-4412

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
05/02/2018
Last modified:
13/03/2018

Description

BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bson_project:bson:3.0.3:*:*:*:*:ruby:*:*