Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pchc-949f-53m5

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Improper Input Validation in multi_xml

multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

Пакеты

Наименование

multi_xml

rubygems
Затронутые версииВерсия исправления

< 0.5.2

0.5.2

EPSS

Процентиль: 79%
0.01272
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 13 лет назад

multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

debian
почти 13 лет назад

multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possib ...

EPSS

Процентиль: 79%
0.01272
Низкий

Дефекты

CWE-20