ADVISORIES
GEM
SEVERITY
CVSS v3.x: 9.8 (Critical)
PATCHED VERSIONS
- ~> 1.12.3
- >= 3.0.4
DESCRIPTION
A flaw in the ObjectId validation regular expression can enable attackers to inject arbitrary information into a given BSON object.
Get Updates: | Via Atom | On Twitter | On GitHub |
CVSS v3.x: 9.8 (Critical)
A flaw in the ObjectId validation regular expression can enable attackers to inject arbitrary information into a given BSON object.