Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fhj9-cjjh-27vm

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Active Record contains deserialization of arbitrary YAML

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

Пакеты

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

< 2.3.17

2.3.17

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

>= 3.0.0, < 3.1.0

3.1.0

EPSS

Процентиль: 91%
0.06742
Низкий

Дефекты

CWE-502

Связанные уязвимости

ubuntu
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

redhat
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

nvd
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

debian
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allow ...

EPSS

Процентиль: 91%
0.06742
Низкий

Дефекты

CWE-502