CVE-2013-0277

EPSS 6.7%

Active Record contains deserialization of arbitrary YAML

發布日:2017/10/24修改日:2026/4/28
也稱為:GHSA-fhj9-cjjh-27vmDEBIAN-CVE-2013-0277

描述

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

受影響套件(2)

參考連結(13)