CVE-2020-10663

HIGH

JSON gem <2.2.0 - Code Injection

Title source: llm

Description

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.

Exploits (1)

nomisec WORKING POC 3 stars
by rails-lts · poc
https://github.com/rails-lts/json_cve_2020_10663

References (19)

Scores

CVSS v3 7.5
EPSS 0.0753
EPSS Percentile 91.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-20
Status published
Products (8)
apple/macos 11.0.1
debian/debian_linux 8.0
debian/debian_linux 10.0
fedoraproject/fedora 30
fedoraproject/fedora 31
json_project/json < 2.2.0
opensuse/leap 15.1
rubygems/json 0 - 2.3.0RubyGems
Published Apr 28, 2020
Tracked Since Feb 18, 2026