CVE-2013-0156
Description
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.
Risk Information
Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
91.907
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2013-0156 are fixed in Ruby-actionpack 2.3.15 | Windows |
| Vulnerabilities CVE-2013-0156 are fixed in Ruby-actionpack 3.0.19 | Windows |
| Vulnerabilities CVE-2013-0156 are fixed in Ruby-actionpack 3.1.10 | Windows |
| Vulnerabilities CVE-2013-0156 are fixed in Ruby-actionpack 3.2.11 | Windows |
| Vulnerabilities CVE-2013-0156 are fixed in Ruby-actionpack for Linux 2.3.15 | Linux |
| Vulnerabilities CVE-2013-0156 are fixed in Ruby-actionpack for Linux 3.0.19 | Linux |
| Vulnerabilities CVE-2013-0156 are fixed in Ruby-actionpack for Linux 3.1.10 | Linux |
| Vulnerabilities CVE-2013-0156 are fixed in Ruby-actionpack for Linux 3.2.11 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234