CVE-2019-13146 Information
Feb 14, 2021
cve
Description
The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS).
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Reference
http://www.securityfocus.com/bid/109114 https://github.com/ankane/field_test/issues/17 https://rubygems.org/gems/field_test
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
5.3
Share on: