ADVISORIES
GEM
SEVERITY
CVSS v3.x: 7.5 (High)
PATCHED VERSIONS
- ~> 1.5.3
- >= 2.0.5
DESCRIPTION
A flaw in the ObjectId validation regular expression can enable attackers to inject arbitrary information into a given BSON object.
Get Updates: | Via Atom | On Twitter | On GitHub |
CVSS v3.x: 7.5 (High)
A flaw in the ObjectId validation regular expression can enable attackers to inject arbitrary information into a given BSON object.