CVE-2014-10077: Improper Input Validation
(updated )
Hash#slice
in lib/i18n/core_ext/hash.rb
in the i18n gem for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key
is present in keep_keys
but not present in the hash.
References
Detect and mitigate CVE-2014-10077 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →