SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-13146

If an application treats arbitrary variants as trusted, this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS).

MEDIUM 5.3EPSS 1.45%

Does this matter?

Lower severity and a low EPSS score (1.45%). Track it; it rarely justifies an emergency change on its own.

Description

The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS).

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
1.45% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-74
Affected
field test project/field test
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.