CVE-2025-27788

JSON is a JSON implementation for Ruby. Starting in version 2.10.0 and prior to version 2.10.2, a specially crafted document could cause an out of bound read, most likely resulting in a crash. Versions prior to 2.10.0 are not vulnerable. Version 2.10.2 fixes the problem. No known workarounds are available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ruby-lang:javascript_object_notation:*:*:*:*:*:ruby:*:*

History

02 Apr 2025, 12:35

Type Values Removed Values Added
References () https://github.com/ruby/json/commit/c56db31f800d5d508389793e69682f99749dbadf - () https://github.com/ruby/json/commit/c56db31f800d5d508389793e69682f99749dbadf - Patch
References () https://github.com/ruby/json/releases/tag/v2.10.2 - () https://github.com/ruby/json/releases/tag/v2.10.2 - Release Notes
References () https://github.com/ruby/json/security/advisories/GHSA-9m3q-rhmv-5q44 - () https://github.com/ruby/json/security/advisories/GHSA-9m3q-rhmv-5q44 - Third Party Advisory
Summary
  • (es) JSON es una implementación de JSON para Ruby. A partir de la versión 2.10.0 y anteriores a la 2.10.2, un documento especialmente manipulado podía provocar una lectura fuera de los límites, lo que probablemente provocaría un bloqueo. Las versiones anteriores a la 2.10.0 no son vulnerables. La versión 2.10.2 soluciona el problema. No se conocen workarounds.
CPE cpe:2.3:a:ruby-lang:javascript_object_notation:*:*:*:*:*:ruby:*:*
First Time Ruby-lang
Ruby-lang javascript Object Notation

12 Mar 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-12 14:15

Updated : 2025-04-02 12:35


NVD link : CVE-2025-27788

Mitre link : CVE-2025-27788

CVE.ORG link : CVE-2025-27788


JSON object : View

Products Affected

ruby-lang

  • javascript_object_notation
CWE
CWE-125

Out-of-bounds Read