gon
If you need to send some data to your js files and you don't want to do this with long way trough views and parsing - use this force!
Activity
- Latest release
- 3mo ago
- Total releases
- 58
- Cadence
- ~23 days
- Last 12 months
- 3
Reach
- Stars
- —
Details
- License
- MIT
- First release
- May 08, 2011
| Version | Released | |
|---|---|---|
7.1.0
minor
|
7.1.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
7.0.0
major
|
7.0.0
major
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
6.6.0
minor
|
6.6.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
6.5.0
minor
|
6.5.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
6.4.0
minor
|
6.4.0
minor
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
6.3.2
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
6.3.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
6.3.1
minor
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
6.3.1
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
6.2.1
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
6.2.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
6.2.0
minor
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
6.2.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
6.1.0
minor
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
6.1.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
6.0.0
major
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
6.0.0
major
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
6.0.1
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
6.0.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
5.2.3
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
5.2.3
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
5.2.2
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
5.2.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
5.2.1
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
5.2.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
5.2.0
minor
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
5.2.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
5.1.2
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
5.1.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
5.1.1
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |
5.1.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
5.1.0
minor
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
5.0.4
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
5.0.3
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
5.0.2
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
5.0.1
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
5.0.0
major
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
4.1.1
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
4.1.0
minor
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
4.0.3
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
4.0.2
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
4.0.1
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
4.0.0
major
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
3.0.5
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
3.0.4
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
3.0.3
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
3.0.2
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
3.0.0
major
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
2.1.2
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
2.2.2
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
2.0.6
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
2.0.5
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
2.0.4
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
2.0.2
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
2.0.3
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
1.1.3
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
1.1.2
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
1.1.1
patch
1 CVE
CVE-2020-25739
GHSA-78vq-9j56-wrfr
Apr 30, 2021
Gon gem lack of escaping certain input when outputting as JSON
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
2.0.0
+ 41 more Show less
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.1.0
2.1.2
2.2.0
2.2.2
2.3.0
3.0.0
3.0.2
3.0.3
3.0.4
3.0.5
4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
6.1.0
6.2.0
6.2.1
6.3.1
6.3.2
Fixed in
6.4.0
References
Updated Feb 19, 2024 · Source: OSV.dev |