CVE-2013-0285

Description

The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
1.5

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2013-0285 are fixed in Ruby-nori 2.0.2Windows
Vulnerabilities CVE-2013-0285 are fixed in Ruby-nori 1.1.4Windows
Vulnerabilities CVE-2013-0285 are fixed in Ruby-nori 1.0.3Windows
Vulnerabilities CVE-2013-0285 are fixed in Ruby-nori for Linux 2.0.2Linux
Vulnerabilities CVE-2013-0285 are fixed in Ruby-nori for Linux 1.1.4Linux
Vulnerabilities CVE-2013-0285 are fixed in Ruby-nori for Linux 1.0.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234