CVE-2015-4412

CRITICAL

Bson < 1.12.3 - Denial of Service

Title source: rule
STIX 2.1

Description

BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75045
Exploit, Patch, Third Party Advisory x_refsource_misc
https://sakurity.com/blog/2015/06/04/mongo_ruby_regexp.html
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1229750
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/06/06/3

Scores

CVSS v3 9.8
EPSS 0.0175
EPSS Percentile 82.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-400
Status published
Products (2)
bson_project/bson 3.0.3
rubygems/bson 0 - 1.12.3RubyGems
Published Feb 05, 2018
Tracked Since Feb 18, 2026