6.1
CVSSv3

CVE-2020-25739

Published: 23/09/2020 Updated: 31/01/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gon project gon

debian debian linux 9.0

canonical ubuntu linux 18.04

Vendor Advisories

Debian Bug report logs - #970938 ruby-gon: CVE-2020-25739 Package: src:ruby-gon; Maintainer for src:ruby-gon is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 25 Sep 2020 20:27:01 UTC Severity: important Tags: secu ...