SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-0156

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection…

HIGH 7.5EPSS 99.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 99.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
99.45% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
rubyonrails/rails · rubyonrails/ruby on rails · debian/debian linux
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.