CVE-2013-1854
Active Record Improper Input Validation
EPSS 3.4%
描述
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.
如何修補 CVE-2013-1854
要修補 CVE-2013-1854,請將受影響套件升級到下列已修補版本。
- Debian/rails—升級至 2.3.14.1 或更新版本
- RubyGems/activerecord—升級至 2.3.18 或更新版本
CVE-2013-1854 正在被利用嗎?
低 — EPSS 為 3.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2.3.14.1
- >= 2.3.0, < 2.3.18