Class: Dawn::Kb::OSVDB_118954
- Inherits:
-
Object
- Object
- Dawn::Kb::OSVDB_118954
- Includes:
- DependencyCheck
- Defined in:
- lib/dawn/kb/osvdb_118954.rb
Overview
Automatically created with rake on 2015-04-04
Constant Summary
Constants included from BasicCheck
Instance Attribute Summary
Attributes included from DependencyCheck
#aux_mitigation_gem, #dependencies, #not_affected, #safe_dependencies, #save_major, #save_minor
Attributes included from BasicCheck
#applies, #aux_links, #check_family, #cve, #cvss, #cwe, #debug, #evidences, #fixes_version, #kind, #message, #mitigated, #name, #osvdb, #owasp, #priority, #release_date, #remediation, #ruby_version, #ruby_vulnerable_versions, #severity, #status, #target_version
Instance Method Summary collapse
-
#initialize ⇒ OSVDB_118954
constructor
include RubyVersionCheck.
Methods included from DependencyCheck
Methods included from BasicCheck
#applies_to?, #cve_link, #cvss_score, families, #family, #family=, #lint, #mitigated?, #nvd_link, #osvdb_link, #rubysec_advisories_link
Methods included from Utils
#__debug_me_and_return, #debug_me, #debug_me_and_return_false, #debug_me_and_return_true
Constructor Details
#initialize ⇒ OSVDB_118954
include RubyVersionCheck
10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 |
# File 'lib/dawn/kb/osvdb_118954.rb', line 10 def initialize = "Ruby on Rails contains a flaw that is triggered when handling a to_json call to ActiveModel::Name, which can cause an infinite loop. This may allow a remote attacker to cause a denial of service." super({ :name=> "OSVDB_118954", :cve=>"", :osvdb=>"118954", :cvss=>"", :release_date => Date.new(2015, 2, 28), :cwe=>"", :owasp=>"A9", :applies=>["rails"], :kind=>Dawn::KnowledgeBase::DEPENDENCY_CHECK, :message=>, :mitigation=>"Currently, there are no known workarounds or upgrades to correct this issue. However, a patch has been committed to the source code repository (e.g. GIT, CVS, SVN) that addresses this vulnerability. Until it is incorporated into the next release of the software, manually patching an existing installation is the only known available solution. Check the vendor links in the references section for more information.", :aux_links=>[""] }) self.safe_dependencies = [{:name=>"rails", :version=>['99.99.99']}] end |