BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.8%