SB2013011810 - Input validation error in ruby-activesupport (Alpine package)



SB2013011810 - Input validation error in ruby-activesupport (Alpine package)

Published: January 18, 2013 Updated: November 15, 2024

Security Bulletin ID SB2013011810
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2013-0156)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.


Remediation

Install update from vendor's website.