CVE-2013-0156
rails - insufficient input validation
EPSS 99.4%
描述
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.
如何修補 CVE-2013-0156
要修補 CVE-2013-0156,請將受影響套件升級到下列已修補版本。
- Debian/rails—升級至 2.3.14.1 或更新版本
- —升級至 2.3.5-1.2+squeeze4.1 或更新版本
- —升級至 2.3.15 或更新版本
CVE-2013-0156 正在被利用嗎?
可能 — EPSS 為 99.4%,屬於高被利用機率區間,建議優先修補。
受影響套件(3)
- from 0, < 2.3.14.1
- from 0, < 2.3.5-1.2+squeeze4.1
- from 0, < 2.3.15