{"id":"CVE-2020-25739","details":"An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.","aliases":["GHSA-78vq-9j56-wrfr"],"modified":"2026-07-08T05:59:56.059381985Z","published":"2020-09-23T14:15:12.947Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"18.04"},{"last_affected":"18.04"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux","cpes":["cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"]},{"source":"CPE_STRING","vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"}]}]},"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/09/msg00018.html"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4560-1/"},{"type":"FIX","url":"https://github.com/gazay/gon/commit/fe3c7b2191a992386dc9edd37de5447a4e809bc7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gazay/gon","events":[{"introduced":"0"},{"fixed":"fe3c7b2191a992386dc9edd37de5447a4e809bc7"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"6.4.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:gon_project:gon:*:*:*:*:*:ruby:*:*"}}],"versions":["v6.3.2","v6.3.1","v6.2.1","v6.2.0","v6.1.0","v6.0.1","v6.0.0","v5.2.3","v5.2.2","v5.2.1","v5.2.0","v5.1.2","v5.1.1","v5.1.0","v5.0.4","v5.0.3","v5.0.2","v5.0.1","v5.0.0","v4.1.1","v4.1.0","v4.0.3","v4.0.2","v4.0.1","v4.0.0beta","v3.0.5","v3.0.4","v3.0.3","v3.0.2","v3.0.0","v2.3.0","v2.2.2","v2.2.0","v2.1.2","v2.1.0","v2.0.6","v2.0.5","v2.0.4","v2.0.3","v2.0.2","v2.0.1","v2.0.0","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.0","v0.3.0","v0.2.2","v0.2.1","v0.2.0","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-25739.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}