7.5

CVE-2013-0175

multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Erik Michaels-ober ≫ Multi Xml Version 0.5.2
   Ruby-lang ≫ Ruby
Erik Michaels-ober ≫ Multi Xml Version 0.5.2
Grape Project ≫ Grape Version 0.1.0
Grape Project ≫ Grape Version 0.1.1
Grape Project ≫ Grape Version 0.1.2
Grape Project ≫ Grape Version 0.1.3
Grape Project ≫ Grape Version 0.1.4
Grape Project ≫ Grape Version 0.1.5
Grape Project ≫ Grape Version 0.2.0
Grape Project ≫ Grape Version 0.2.1
Grape Project ≫ Grape Version 0.2.2
Grape Project ≫ Grape Version 0.2.3
Grape Project ≫ Grape Version 0.2.4
Grape Project ≫ Grape Version 0.2.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.73% 0.888
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.openwall.com/lists/oss-security/2013/01/11/9
https://gist.github.com/nate/d7f6d9f4925f413621aa
https://github.com/sferik/multi_xml/pull/34
https://groups.google.com/forum/?fromgroups=#%21topic/ruby-grape/fthDkMgIOa0
https://news.ycombinator.com/item?id=5040457