CVE-2013-0277
published 2013-02-13CVE-2013-0277: ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted…
PriorityP348critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.50%
93.8th percentile
ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activerecord_project | activerecord | >= 0 < 2.3.17 | 2.3.17 |
| activerecord_project | activerecord | >= 3.0.0 < 3.1.0 | 3.1.0 |
| debian | rails | < rails 2.3.14.1 (bookworm) | rails 2.3.14.1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-activerecord: Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0
vendor_redhat·2013-02-11·CVSS 10.0
CVE-2013-0277 [CRITICAL] CWE-502 rubygem-activerecord: Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0
rubygem-activerecord: Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0
ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.
Package: ruby193-rubygem-activesupport (OpenShift Enterprise 1) - Not affected
Package: rubygem-activesupport (OpenShift Enterprise 1) - Affected
Package: rubygem-activesupport (Red Hat Subscription Asset Manager) - Affected
Debian
CVE-2013-0277: rails - ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote a...
vendor_debian·2013·CVSS 10.0
CVE-2013-0277 [CRITICAL] CVE-2013-0277: rails - ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote a...
ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: resolved (fixed in 2.3.14.1)
sid: resolved (fixed in 2.3.14.1)
trixie: resolved (fixed in 2.3.14.1)
OSV
Active Record contains deserialization of arbitrary YAML
osv·2017-10-24
CVE-2013-0277 [CRITICAL] Active Record contains deserialization of arbitrary YAML
Active Record contains deserialization of arbitrary YAML
ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.
GHSA
Active Record contains deserialization of arbitrary YAML
ghsa·2017-10-24
CVE-2013-0277 [CRITICAL] CWE-502 Active Record contains deserialization of arbitrary YAML
Active Record contains deserialization of arbitrary YAML
ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.
OSV
CVE-2013-0277: ActiveRecord in Ruby on Rails before 2
osv·2013-02-13·CVSS 10.0
CVE-2013-0277 [CRITICAL] CVE-2013-0277: ActiveRecord in Ruby on Rails before 2
ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0277 rubygem-activerecord: Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [fedora-all]
bugzilla·2013-04-07·CVSS 10.0
CVE-2013-0277 [CRITICAL] CVE-2013-0277 rubygem-activerecord: Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [fedora-all]
CVE-2013-0277 rubygem-activerecord: Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avai
Bugzilla
CVE-2013-0277 rubygem-activerecord: Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0
bugzilla·2013-02-10·CVSS 10.0
CVE-2013-0277 [CRITICAL] CVE-2013-0277 rubygem-activerecord: Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0
CVE-2013-0277 rubygem-activerecord: Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0
Aaron Patterson ([email protected]) reports:
Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0
There is a vulnerability in the serialized attribute handling code in Ruby on
Rails 2.3 and 3.0, applications which allow users to directly assign to the
serialized fields in their models are at risk of Denial of Service or Remote
Code Execution vulnerabilities. This vulnerability has been assigned the CVE
identifier CVE-2013-0277
Versions Affected: 2.3.x, 3.0.x and all earlier versions
Not affected: 3.1.0 and Above
Fixed Versions: None
Impact
The +serialize+ helper in Active Record allows developers to store various
objects serialized to a BLOB column in the database. The
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-03/msg00048.htmlhttp://secunia.com/advisories/52112http://securitytracker.com/id?1028109http://support.apple.com/kb/HT5784http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/http://www.debian.org/security/2013/dsa-2620http://www.openwall.com/lists/oss-security/2013/02/11/6http://www.osvdb.org/90073https://groups.google.com/group/rubyonrails-security/msg/302ec7ce90f13837?dmode=source&output=gplainhttps://puppet.com/security/cve/cve-2013-0277http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-03/msg00048.htmlhttp://secunia.com/advisories/52112http://securitytracker.com/id?1028109http://support.apple.com/kb/HT5784http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/http://www.debian.org/security/2013/dsa-2620http://www.openwall.com/lists/oss-security/2013/02/11/6http://www.osvdb.org/90073https://groups.google.com/group/rubyonrails-security/msg/302ec7ce90f13837?dmode=source&output=gplainhttps://puppet.com/security/cve/cve-2013-0277
2013-02-13
Published