CVE-2013-1801
HTTParty does not restrict casts of string values
EPSS 4.4%
Description
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156.
How to fix CVE-2013-1801
To remediate CVE-2013-1801, upgrade the affected package to a fixed version below.
- RubyGems/httparty—upgrade to 0.10.0 or later
Is CVE-2013-1801 being exploited?
Low — EPSS is 4.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.10.0