10
CVSSv2

CVE-2013-0277

Published: 13/02/2013 Updated: 08/08/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

ActiveRecord in Ruby on Rails prior to 2.3.17 and 3.x prior to 3.1.0 allows remote malicious users to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

Vulnerable Product Search on Vulmon Subscribe to Product

rubyonrails rails 3.0.7

rubyonrails rails 3.0.16

rubyonrails rails 3.0.9

rubyonrails rails 3.0.5

rubyonrails rails 3.0.2

rubyonrails rails 3.0.12

rubyonrails rails 3.0.13

rubyonrails rails 3.0.0

rubyonrails rails 3.0.4

rubyonrails rails 3.0.14

rubyonrails rails 3.0.1

rubyonrails rails 3.0.19

rubyonrails rails 3.0.8

rubyonrails rails 3.0.6

rubyonrails ruby on rails 3.0.4

rubyonrails rails 3.0.3

rubyonrails rails 3.0.11

rubyonrails rails 3.0.20

rubyonrails rails 3.0.17

rubyonrails rails 3.0.18

rubyonrails rails 3.0.10

rubyonrails rails 2.3.14

rubyonrails rails 2.3.13

rubyonrails rails 2.3.10

rubyonrails rails 2.3.16

rubyonrails rails 2.3.11

rubyonrails rails 2.3.12

rubyonrails rails 2.3.9

rubyonrails rails 2.3.4

rubyonrails rails 2.3.3

rubyonrails rails 2.3.2

rubyonrails rails 2.3.15

rubyonrails rails 2.3.0

rubyonrails rails 2.3.1

Vendor Advisories

Two vulnerabilities were discovered in Ruby on Rails, a Ruby framework for web application development CVE-2013-0276 The blacklist provided by the attr_protected method could be bypassed with crafted requests, having an application-specific impact CVE-2013-0277 In some applications, the +serialize+ helper in ActiveRecord could be tricked in ...