Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-2015-4410.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
mongodb/bson-ruby 资源管理错误漏洞
Vulnerability Description
BSON是RubyGems组织的一个类json(把一个对象转化为二进制数字)的编程语言实现的数据格式。mongodb/bson-ruby是一个用在MongoDB中的BSON规范(2.0.0+)的Ruby实现。 mongodb/bson-ruby 3.0.4之前版本(使用在rubygem-moped中)中的Moped::BSON::ObjecId.legal?方法中存在安全漏洞。远程攻击者可利用该漏洞通过特制的字符串造成拒绝服务(工作资源消耗)。注意:该漏洞是由于对CNNVD-201601-098(CVE-
CVSS Information
N/A
Vulnerability Type
N/A