Back to search
CVE-2013-0277
Published: Feb 13, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
1028109
vdb-entry
x_refsource_SECTRACK
https://puppet.com/security/cve/cve-2013-0277
x_refsource_CONFIRM
http://support.apple.com/kb/HT5784
x_refsource_CONFIRM
DSA-2620
vendor-advisory
x_refsource_DEBIAN
APPLE-SA-2013-06-04-1
vendor-advisory
x_refsource_APPLE
90073
vdb-entry
x_refsource_OSVDB
[rubyonrails-security] 20130211 Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]
mailing-list
x_refsource_MLIST
openSUSE-SU-2013:0462
vendor-advisory
x_refsource_SUSE
[oss-security] 20130211 Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]
mailing-list
x_refsource_MLIST
52112
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now