Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted string.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
rubygem-moped 输入验证错误漏洞
Vulnerability Description
rubygem-moped是一个用于Ruby的MongoDB驱动程序。 rubygem-moped commit dd5a7c14b5d2e466f7875d079af71ad19774609b之前版本中的Moped::BSON::ObjecId.legal?方法存在安全漏洞。远程攻击者通过特制的字符串利用该漏洞导致拒绝服务(工作资源消耗)或执行跨站点脚本(XSS)攻击。
CVSS Information
N/A
Vulnerability Type
N/A