5

CVE-2013-6414

actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.

Data is provided by the National Vulnerability Database (NVD)
RubyonrailsRails Update- Version <= 4.0.1
RubyonrailsRails Version4.0.0 Update-
RubyonrailsRails Version4.0.0 Updatebeta
RubyonrailsRails Version4.0.0 Updaterc1
RubyonrailsRails Version4.0.0 Updaterc2
RubyonrailsRails Version4.0.1 Updaterc1
RubyonrailsRails Version3.0.0
RubyonrailsRails Version3.0.0 Updatebeta
RubyonrailsRails Version3.0.0 Updatebeta2
RubyonrailsRails Version3.0.0 Updatebeta3
RubyonrailsRails Version3.0.0 Updatebeta4
RubyonrailsRails Version3.0.0 Updaterc
RubyonrailsRails Version3.0.0 Updaterc2
RubyonrailsRails Version3.0.1
RubyonrailsRails Version3.0.1 Updatepre
RubyonrailsRails Version3.0.2
RubyonrailsRails Version3.0.2 Updatepre
RubyonrailsRails Version3.0.3
RubyonrailsRails Version3.0.4 Updaterc1
RubyonrailsRails Version3.0.5
RubyonrailsRails Version3.0.5 Updaterc1
RubyonrailsRails Version3.0.6
RubyonrailsRails Version3.0.6 Updaterc1
RubyonrailsRails Version3.0.6 Updaterc2
RubyonrailsRails Version3.0.7
RubyonrailsRails Version3.0.7 Updaterc1
RubyonrailsRails Version3.0.7 Updaterc2
RubyonrailsRails Version3.0.8
RubyonrailsRails Version3.0.8 Updaterc1
RubyonrailsRails Version3.0.8 Updaterc2
RubyonrailsRails Version3.0.8 Updaterc3
RubyonrailsRails Version3.0.8 Updaterc4
RubyonrailsRails Version3.0.9
RubyonrailsRails Version3.0.9 Updaterc1
RubyonrailsRails Version3.0.9 Updaterc2
RubyonrailsRails Version3.0.9 Updaterc3
RubyonrailsRails Version3.0.9 Updaterc4
RubyonrailsRails Version3.0.9 Updaterc5
RubyonrailsRails Version3.0.10
RubyonrailsRails Version3.0.10 Updaterc1
RubyonrailsRails Version3.0.11
RubyonrailsRails Version3.0.12
RubyonrailsRails Version3.0.12 Updaterc1
RubyonrailsRails Version3.0.13
RubyonrailsRails Version3.0.13 Updaterc1
RubyonrailsRails Version3.0.14
RubyonrailsRails Version3.0.16
RubyonrailsRails Version3.0.17
RubyonrailsRails Version3.0.18
RubyonrailsRails Version3.0.19
RubyonrailsRails Version3.0.20
RubyonrailsRails Version3.1.0
RubyonrailsRails Version3.1.0 Updatebeta1
RubyonrailsRails Version3.1.0 Updaterc1
RubyonrailsRails Version3.1.0 Updaterc2
RubyonrailsRails Version3.1.0 Updaterc3
RubyonrailsRails Version3.1.0 Updaterc4
RubyonrailsRails Version3.1.0 Updaterc5
RubyonrailsRails Version3.1.0 Updaterc6
RubyonrailsRails Version3.1.0 Updaterc7
RubyonrailsRails Version3.1.0 Updaterc8
RubyonrailsRails Version3.1.1
RubyonrailsRails Version3.1.1 Updaterc1
RubyonrailsRails Version3.1.1 Updaterc2
RubyonrailsRails Version3.1.1 Updaterc3
RubyonrailsRails Version3.1.2
RubyonrailsRails Version3.1.2 Updaterc1
RubyonrailsRails Version3.1.2 Updaterc2
RubyonrailsRails Version3.1.3
RubyonrailsRails Version3.1.4
RubyonrailsRails Version3.1.4 Updaterc1
RubyonrailsRails Version3.1.5
RubyonrailsRails Version3.1.5 Updaterc1
RubyonrailsRails Version3.1.6
RubyonrailsRails Version3.1.7
RubyonrailsRails Version3.1.8
RubyonrailsRails Version3.1.9
RubyonrailsRails Version3.1.10
RubyonrailsRails Version3.2.0
RubyonrailsRails Version3.2.0 Updaterc1
RubyonrailsRails Version3.2.0 Updaterc2
RubyonrailsRails Version3.2.1
RubyonrailsRails Version3.2.2
RubyonrailsRails Version3.2.2 Updaterc1
RubyonrailsRails Version3.2.3
RubyonrailsRails Version3.2.3 Updaterc1
RubyonrailsRails Version3.2.3 Updaterc2
RubyonrailsRails Version3.2.4
RubyonrailsRails Version3.2.4 Updaterc1
RubyonrailsRails Version3.2.5
RubyonrailsRails Version3.2.6
RubyonrailsRails Version3.2.7
RubyonrailsRails Version3.2.8
RubyonrailsRails Version3.2.9
RubyonrailsRails Version3.2.10
RubyonrailsRails Version3.2.11
RubyonrailsRails Version3.2.12
RubyonrailsRails Version3.2.13
RubyonrailsRails Version3.2.13 Updaterc1
RubyonrailsRails Version3.2.13 Updaterc2
RubyonrailsRuby On Rails Version <= 3.2.15
RubyonrailsRuby On Rails Version3.0.4
RubyonrailsRuby On Rails Version3.1.11
RubyonrailsRuby On Rails Version3.2.14
RubyonrailsRuby On Rails Version3.2.14 Updaterc1
RubyonrailsRuby On Rails Version3.2.14 Updaterc2
RubyonrailsRuby On Rails Version3.2.15 Updaterc1
RubyonrailsRuby On Rails Version3.2.15 Updaterc2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 70.84% 0.985
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.