CVE-2020-25739
published 2020-09-23CVE-2020-25739: An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.38%
69.3th percentile
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | ruby-gon | < ruby-gon 6.4.0-1 (bookworm) | ruby-gon 6.4.0-1 (bookworm) |
| gon_project | gon | < 6.4.0 | 6.4.0 |
| gon_project | gon | >= 0 < 6.4.0 | 6.4.0 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Gon gem lack of escaping certain input when outputting as JSON
osv·2021-04-30
CVE-2020-25739 [MEDIUM] Gon gem lack of escaping certain input when outputting as JSON
Gon gem lack of escaping certain input when outputting as JSON
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.
GHSA
Gon gem lack of escaping certain input when outputting as JSON
ghsa·2021-04-30
CVE-2020-25739 [MEDIUM] CWE-79 Gon gem lack of escaping certain input when outputting as JSON
Gon gem lack of escaping certain input when outputting as JSON
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.
OSV
CVE-2020-25739: An issue was discovered in the gon gem before gon-6
osv·2020-09-23·CVSS 6.1
CVE-2020-25739 [MEDIUM] CVE-2020-25739: An issue was discovered in the gon gem before gon-6
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.
Ubuntu
Gon gem vulnerability
vendor_ubuntu·2020-09-30
CVE-2020-25739 Gon gem vulnerability
Title: Gon gem vulnerability
Summary: Gon gem could be made to run programs if it received specially crafted network
traffic.
It was discovered that Gon gem did not properly escape certain input. An
attacker could use this vulnerability to execute a cross-site scripting
(XSS) attack.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-25739: ruby-gon - An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does...
vendor_debian·2020·CVSS 6.1
CVE-2020-25739 [MEDIUM] CVE-2020-25739: ruby-gon - An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does...
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.
Scope: local
bookworm: resolved (fixed in 6.4.0-1)
bullseye: resolved (fixed in 6.4.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/gazay/gon/commit/fe3c7b2191a992386dc9edd37de5447a4e809bc7https://lists.debian.org/debian-lts-announce/2020/09/msg00018.htmlhttps://usn.ubuntu.com/4560-1/https://github.com/gazay/gon/commit/fe3c7b2191a992386dc9edd37de5447a4e809bc7https://lists.debian.org/debian-lts-announce/2020/09/msg00018.htmlhttps://usn.ubuntu.com/4560-1/
2020-09-23
Published