Sha256: c26b1e08336d35c7216d21ee7fe46e5d68de4dcb30521eef46f27778e29be785

Contents?: true

Size: 573 Bytes

Versions: 1

Compression:

Stored size: 573 Bytes

Contents

---
gem: sentry-raven
cve: 2014-9490
osvdb: 115654
url: https://nvd.nist.gov/vuln/detail/CVE-2014-9490
title: sentry-raven Gem for Ruby contains a flaw that can result in a denial of service
date: 2014-12-08
description: Sentry raven-ruby contains a flaw in the lib/raven/okjson.rb script
  that is triggered when large numeric values are stored as an exponent or in
  scientific notation. With a specially crafted request, an attacker can cause
  the software to consume excessive resources resulting in a denial of service.
cvss_v2: 5.0
patched_versions:
  - ">= 0.12.2"

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/sentry-raven/CVE-2014-9490.yml