Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0277

Опубликовано: 11 фев. 2013
Источник: redhat
CVSS2: 7.5

Описание

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1ruby193-rubygem-activesupportNot affected
OpenShift Enterprise 1rubygem-activesupportAffected
Red Hat CloudForms Tools 1rubygem-activesupportWill not fix
Red Hat Subscription Asset Managerrubygem-activesupportAffected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=909633rubygem-activerecord: Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0

7.5 High

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

nvd
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

debian
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allow ...

github
больше 8 лет назад

Active Record contains deserialization of arbitrary YAML

7.5 High

CVSS2