-
Notifications
You must be signed in to change notification settings - Fork 8
Open
Description
Sonar picks up a vulnerability in version 0.2.3:
Filename: rubygems-0.2.3.war/META-INF/maven/org.jruby.mains/jruby-mains/pom.xml | Reference: CVE-2011-4838 | CVSS Score: 7.8 | Category: CWE-20 Improper Input Validation | JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
It seems like the current POM for 0.2.4-SNAPSHOT would fix this?
Metadata
Metadata
Assignees
Labels
No labels