CVE-2020-10663 vulnerability in Debian and Other Products
Published on April 28, 2020
The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.
Products Associated with CVE-2020-10663
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-10663 are published in these products:
Exploit Probability
EPSS
7.53%
Percentile
91.66%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.