Описание
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.
Отчет
For details of affected products and workarounds see https://access.redhat.com/knowledge/node/290903
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat CloudForms Tools 1 | rubygem-activesupport | Affected | ||
| CloudForms for RHEL 6 | rubygem-actionpack | Fixed | RHSA-2013:0155 | 10.01.2013 |
| CloudForms for RHEL 6 | rubygem-activerecord | Fixed | RHSA-2013:0155 | 10.01.2013 |
| CloudForms for RHEL 6 | rubygem-activesupport | Fixed | RHSA-2013:0155 | 10.01.2013 |
| Red Hat Subscription Asset Manager 1.1 | rubygem-actionpack | Fixed | RHSA-2013:0154 | 10.01.2013 |
| Red Hat Subscription Asset Manager 1.1 | rubygem-activerecord | Fixed | RHSA-2013:0154 | 10.01.2013 |
| Red Hat Subscription Asset Manager 1.1 | rubygem-activesupport | Fixed | RHSA-2013:0154 | 10.01.2013 |
| RHEL 6 Version of OpenShift Enterprise | ruby193-rubygem-actionpack | Fixed | RHSA-2013:0153 | 10.01.2013 |
| RHEL 6 Version of OpenShift Enterprise | ruby193-rubygem-activesupport | Fixed | RHSA-2013:0153 | 10.01.2013 |
| RHEL 6 Version of OpenShift Enterprise | rubygem-actionpack | Fixed | RHSA-2013:0153 | 10.01.2013 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS2
Связанные уязвимости
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2. ...
EPSS
7.5 High
CVSS2