Unsafe Object Creation Vulnerability in JSON

Hi,
There is vulnerability reported on json version used in ruby https://www.ruby-lang.org/en/news/2020/03/19/json-dos-cve-2020-10663/
The ruby version used in latest Logstash contains this json version, which contains this vulnerability.
Does Logstash becomes vulnerable for receiving JSON input by TCP or Beats input?

Thanks and Regards,

Sunil

Think Logstash uses jRuby and it's not effected by this CVE according to the below. But there could be some use of Ruby somewhere I suppose.

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.