Skip to content

No-Jira(deps): [Security] Bump json from 2.1.0 to 2.3.1 - #53

Closed
dependabot-preview[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/json-2.3.1
Closed

No-Jira(deps): [Security] Bump json from 2.1.0 to 2.3.1#53
dependabot-preview[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/json-2.3.1

Conversation

@dependabot-preview

@dependabot-preview dependabot-preview Bot commented Jun 30, 2020

Copy link
Copy Markdown
Contributor

Bumps json from 2.1.0 to 2.3.1. This update includes a security fix.

Vulnerabilities fixed

Sourced from The Ruby Advisory Database.

json Gem for Ruby Unsafe Object Creation Vulnerability (additional fix) There is an unsafe object creation vulnerability in the json gem bundled with Ruby. This vulnerability has been assigned the CVE identifier CVE-2020-10663. We strongly recommend upgrading the json gem.

Details

When parsing certain JSON documents, the json gem (including the one bundled with Ruby) can be coerced into creating arbitrary objects in the target system.

This is the same issue as CVE-2013-0269. The previous fix was incomplete, which addressed JSON.parse(user_input), but didn’t address some other styles of JSON parsing including JSON(user_input) and JSON.parse(user_input, nil).

See CVE-2013-0269 in detail. Note that the issue was exploitable to cause a Denial of Service by creating many garbage-uncollectable Symbol objects, but this kind of attack is no longer valid because Symbol objects are now garbage-collectable. However, creating arbitrary objects may cause severe security consequences depending upon the application code.

Patched versions: >= 2.3.0 Unaffected versions: none

Changelog

Sourced from json's changelog.

Changes

2019-12-11 (2.3.0)

  • Fix default of create_additions to always be false for JSON(user_input) and JSON.parse(user_input, nil). Note that JSON.load remains with default true and is meant for internal serialization of trusted data. [CVE-2020-10663]
  • Fix passing args all #to_json in json/add/*.
  • Fix encoding issues
  • Fix issues of keyword vs positional parameter
  • Fix JSON::Parser against bigdecimal updates
  • Bug fixes to JRuby port

2019-02-21 (2.2.0)

  • Adds support for 2.6 BigDecimal and ruby standard library Set datetype.
Commits
  • 0951d77 Bump version to 2.3.1
  • ddc29e2 Merge pull request #429 from flori/remove-generate-task-for-gemspec
  • cee8020 Removed gemspec task from default task on Rakefile
  • 9fd6371 Use VERSION file instead of hard-coded value
  • dc90bcf Removed explicitly date field in gemspec, it will assign by rubygems.org
  • 4c11a40 Removed task for json_pure.gemspec
  • e794ec9 Merge pull request #426 from marcandre/indent
  • 7cc9301 Merge pull request #428 from marcandre/change_fix
  • 9e2a1fb Make changes more precise #424
  • f8fa987 Merge pull request #424 from marcandre/update_changes
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in the .dependabot/config.yml file in this repo:

  • Update frequency
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview Bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Jun 30, 2020
@dependabot-preview
dependabot-preview Bot force-pushed the dependabot/bundler/json-2.3.1 branch 3 times, most recently from 041970c to 28ca4d6 Compare August 11, 2020 15:31
@dependabot-preview
dependabot-preview Bot force-pushed the dependabot/bundler/json-2.3.1 branch from 28ca4d6 to c710caa Compare August 13, 2020 21:43
@dependabot-preview
dependabot-preview Bot force-pushed the dependabot/bundler/json-2.3.1 branch from c710caa to 22e9c0d Compare September 8, 2020 20:19
@dependabot-preview
dependabot-preview Bot force-pushed the dependabot/bundler/json-2.3.1 branch 2 times, most recently from 89fb8aa to 3330fff Compare September 24, 2020 18:53
@dependabot-preview
dependabot-preview Bot force-pushed the dependabot/bundler/json-2.3.1 branch from 3330fff to 5575c26 Compare October 12, 2020 15:25
@dependabot-preview
dependabot-preview Bot force-pushed the dependabot/bundler/json-2.3.1 branch 2 times, most recently from 3bdf923 to ff5e606 Compare November 25, 2020 15:55
Bumps [json](https://github.com/flori/json) from 2.1.0 to 2.3.1. **This update includes a security fix.**
- [Release notes](https://github.com/flori/json/releases)
- [Changelog](https://github.com/flori/json/blob/master/CHANGES.md)
- [Commits](ruby/json@v2.1.0...v2.3.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview
dependabot-preview Bot force-pushed the dependabot/bundler/json-2.3.1 branch from ff5e606 to 2065b44 Compare December 11, 2020 16:07
@dependabot-preview

Copy link
Copy Markdown
Contributor Author

Superseded by #75.

@dependabot-preview
dependabot-preview Bot deleted the dependabot/bundler/json-2.3.1 branch December 15, 2020 10:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants