Back

HIGH

rubygem-activesupport: Multiple vulnerabilities in parameter parsing in ActionPack

Published Jan 13, 2013

Description

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.

Affected products

Remediation

Red Hat statement

For details of affected products and workarounds see https://access.redhat.com/knowledge/node/290903

Metrics

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 13, 2013
Updated Aug 6, 2024
Reserved Dec 6, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Jan 8, 2013
GHSA-JMGW-6VJG-JJWG