5.8

CVE-2013-1856

The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.

Data is provided by the National Vulnerability Database (NVD)
RubyonrailsRails Version3.1.0
RubyonrailsRails Version3.1.0 Updatebeta1
RubyonrailsRails Version3.1.0 Updaterc1
RubyonrailsRails Version3.1.0 Updaterc2
RubyonrailsRails Version3.1.0 Updaterc3
RubyonrailsRails Version3.1.0 Updaterc4
RubyonrailsRails Version3.1.0 Updaterc5
RubyonrailsRails Version3.1.0 Updaterc6
RubyonrailsRails Version3.1.0 Updaterc7
RubyonrailsRails Version3.1.0 Updaterc8
RubyonrailsRails Version3.1.1
RubyonrailsRails Version3.1.1 Updaterc1
RubyonrailsRails Version3.1.1 Updaterc2
RubyonrailsRails Version3.1.1 Updaterc3
RubyonrailsRails Version3.1.2
RubyonrailsRails Version3.1.2 Updaterc1
RubyonrailsRails Version3.1.2 Updaterc2
RubyonrailsRails Version3.1.3
RubyonrailsRails Version3.1.4
RubyonrailsRails Version3.1.4 Updaterc1
RubyonrailsRails Version3.1.5
RubyonrailsRails Version3.1.5 Updaterc1
RubyonrailsRails Version3.1.6
RubyonrailsRails Version3.1.7
RubyonrailsRails Version3.1.8
RubyonrailsRails Version3.1.9
RubyonrailsRails Version3.1.10
RubyonrailsRails Version3.2.0
RubyonrailsRails Version3.2.0 Updaterc1
RubyonrailsRails Version3.2.0 Updaterc2
RubyonrailsRails Version3.2.1
RubyonrailsRails Version3.2.2
RubyonrailsRails Version3.2.2 Updaterc1
RubyonrailsRails Version3.2.3
RubyonrailsRails Version3.2.3 Updaterc1
RubyonrailsRails Version3.2.3 Updaterc2
RubyonrailsRails Version3.2.4
RubyonrailsRails Version3.2.4 Updaterc1
RubyonrailsRails Version3.2.5
RubyonrailsRails Version3.2.6
RubyonrailsRails Version3.2.7
RubyonrailsRails Version3.2.8
RubyonrailsRails Version3.2.9
RubyonrailsRails Version3.2.10
RubyonrailsRails Version3.2.11
RubyonrailsRails Version3.2.12
RubyonrailsRuby On Rails Version3.1.11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.77% 0.712
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.