5

CVE-2014-0082

actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RubyonrailsRails Version3.0.0
RubyonrailsRails Version3.0.0 Updatebeta
RubyonrailsRails Version3.0.0 Updatebeta2
RubyonrailsRails Version3.0.0 Updatebeta3
RubyonrailsRails Version3.0.0 Updatebeta4
RubyonrailsRails Version3.0.0 Updaterc
RubyonrailsRails Version3.0.0 Updaterc2
RubyonrailsRails Version3.0.1
RubyonrailsRails Version3.0.1 Updatepre
RubyonrailsRails Version3.0.2
RubyonrailsRails Version3.0.2 Updatepre
RubyonrailsRails Version3.0.3
RubyonrailsRails Version3.0.4 Updaterc1
RubyonrailsRails Version3.0.5
RubyonrailsRails Version3.0.5 Updaterc1
RubyonrailsRails Version3.0.6
RubyonrailsRails Version3.0.6 Updaterc1
RubyonrailsRails Version3.0.6 Updaterc2
RubyonrailsRails Version3.0.7
RubyonrailsRails Version3.0.7 Updaterc1
RubyonrailsRails Version3.0.7 Updaterc2
RubyonrailsRails Version3.0.8
RubyonrailsRails Version3.0.8 Updaterc1
RubyonrailsRails Version3.0.8 Updaterc2
RubyonrailsRails Version3.0.8 Updaterc3
RubyonrailsRails Version3.0.8 Updaterc4
RubyonrailsRails Version3.0.9
RubyonrailsRails Version3.0.9 Updaterc1
RubyonrailsRails Version3.0.9 Updaterc2
RubyonrailsRails Version3.0.9 Updaterc3
RubyonrailsRails Version3.0.9 Updaterc4
RubyonrailsRails Version3.0.9 Updaterc5
RubyonrailsRails Version3.0.10
RubyonrailsRails Version3.0.10 Updaterc1
RubyonrailsRails Version3.0.11
RubyonrailsRails Version3.0.12
RubyonrailsRails Version3.0.12 Updaterc1
RubyonrailsRails Version3.0.13
RubyonrailsRails Version3.0.13 Updaterc1
RubyonrailsRails Version3.0.14
RubyonrailsRails Version3.0.16
RubyonrailsRails Version3.0.17
RubyonrailsRails Version3.0.18
RubyonrailsRails Version3.0.19
RubyonrailsRails Version3.0.20
RubyonrailsRails Version3.1.0
RubyonrailsRails Version3.1.0 Updatebeta1
RubyonrailsRails Version3.1.0 Updaterc1
RubyonrailsRails Version3.1.0 Updaterc2
RubyonrailsRails Version3.1.0 Updaterc3
RubyonrailsRails Version3.1.0 Updaterc4
RubyonrailsRails Version3.1.0 Updaterc5
RubyonrailsRails Version3.1.0 Updaterc6
RubyonrailsRails Version3.1.0 Updaterc7
RubyonrailsRails Version3.1.0 Updaterc8
RubyonrailsRails Version3.1.1
RubyonrailsRails Version3.1.1 Updaterc1
RubyonrailsRails Version3.1.1 Updaterc2
RubyonrailsRails Version3.1.1 Updaterc3
RubyonrailsRails Version3.1.2
RubyonrailsRails Version3.1.2 Updaterc1
RubyonrailsRails Version3.1.2 Updaterc2
RubyonrailsRails Version3.1.3
RubyonrailsRails Version3.1.4
RubyonrailsRails Version3.1.4 Updaterc1
RubyonrailsRails Version3.1.5
RubyonrailsRails Version3.1.5 Updaterc1
RubyonrailsRails Version3.1.6
RubyonrailsRails Version3.1.7
RubyonrailsRails Version3.1.8
RubyonrailsRails Version3.1.9
RubyonrailsRails Version3.1.10
RubyonrailsRails Version3.2.0
RubyonrailsRails Version3.2.0 Updaterc1
RubyonrailsRails Version3.2.0 Updaterc2
RubyonrailsRails Version3.2.1
RubyonrailsRails Version3.2.2
RubyonrailsRails Version3.2.2 Updaterc1
RubyonrailsRails Version3.2.3
RubyonrailsRails Version3.2.3 Updaterc1
RubyonrailsRails Version3.2.3 Updaterc2
RubyonrailsRails Version3.2.4
RubyonrailsRails Version3.2.4 Updaterc1
RubyonrailsRails Version3.2.5
RubyonrailsRails Version3.2.6
RubyonrailsRails Version3.2.7
RubyonrailsRails Version3.2.8
RubyonrailsRails Version3.2.9
RubyonrailsRails Version3.2.10
RubyonrailsRails Version3.2.11
RubyonrailsRails Version3.2.12
RubyonrailsRails Version3.2.13
RubyonrailsRails Version3.2.13 Updaterc1
RubyonrailsRails Version3.2.13 Updaterc2
RubyonrailsRails Version3.2.15
RubyonrailsRails Version3.2.15 Updaterc3
RubyonrailsRuby On Rails Version <= 3.2.16
RubyonrailsRuby On Rails Version3.0.4
RubyonrailsRuby On Rails Version3.2.14
RubyonrailsRuby On Rails Version3.2.14 Updaterc1
RubyonrailsRuby On Rails Version3.2.14 Updaterc2
RubyonrailsRuby On Rails Version3.2.15 Updaterc1
RubyonrailsRuby On Rails Version3.2.15 Updaterc2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.46% 0.907
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.