CVE-2013-0333
rails - insufficient input validation
EPSS 98.6%
描述
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct SQL injection attacks, or bypass authentication via crafted data that triggers unsafe decoding, a different vulnerability than CVE-2013-0156.
如何修補 CVE-2013-0333
要修補 CVE-2013-0333,請將受影響套件升級到下列已修補版本。
- Debian/rails—升級至 2.3.14.1 或更新版本
- Debian/rails—升級至 2.3.5-1.2+squeeze6 或更新版本
- —升級至 2.3.16 或更新版本
CVE-2013-0333 正在被利用嗎?
可能 — EPSS 為 98.6%,屬於高被利用機率區間,建議優先修補。
受影響套件(3)
- from 0, < 2.3.14.1
- from 0, < 2.3.5-1.2+squeeze6
- >= 2.3.2, < 2.3.16