field_test gem contains injection vulnerability
Moderate severity
GitHub Reviewed
Published
Jul 16, 2019
to the GitHub Advisory Database
•
Updated Jul 5, 2023
Description
Published by the National Vulnerability Database
Jul 9, 2019
Reviewed
Jul 15, 2019
Published to the GitHub Advisory Database
Jul 16, 2019
Last updated
Jul 5, 2023
The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS).
References