CVE-2013-1854
published 2013-03-19CVE-2013-1854: The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.44%
87.6th percentile
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activerecord_project | activerecord | >= 2.3.0 < 2.3.18 | 2.3.18 |
| activerecord_project | activerecord | >= 3.1.0 < 3.1.12 | 3.1.12 |
| activerecord_project | activerecord | >= 3.2.0 < 3.2.13 | 3.2.13 |
| debian | rails | < rails 2.3.14.1 (bookworm) | rails 2.3.14.1 (bookworm) |
| redhat | enterprise_linux | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-activerecord: attribute_dos Symbol DoS vulnerability
vendor_redhat·2013-03-18·CVSS 5.0
CVE-2013-1854 [MEDIUM] CWE-400 rubygem-activerecord: attribute_dos Symbol DoS vulnerability
rubygem-activerecord: attribute_dos Symbol DoS vulnerability
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.
A flaw was found in the way Ruby on Rails handled hashes in certain queries. A remote attacker could use this flaw to perform a denial of service (resource consumption) attack by sending specially crafted queries that would result in the creation of Ruby symbols, which were never garbage collected.
Package: rubygem-activerecord (OpenShift Enterprise 1) - Not affected
Package: ruby193-rubygem-activerecord (Red Hat Satellite 6) - Affected
Package: rubygem-activer
Debian
CVE-2013-1854: rails - The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3...
vendor_debian·2013·CVSS 5.0
CVE-2013-1854 [MEDIUM] CVE-2013-1854: rails - The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3...
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: resolved (fixed in 2.3.14.1)
sid: resolved (fixed in 2.3.14.1)
trixie: resolved (fixed in 2.3.14.1)
OSV
Active Record Improper Input Validation
osv·2017-10-24
CVE-2013-1854 [MEDIUM] Active Record Improper Input Validation
Active Record Improper Input Validation
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.
GHSA
Active Record Improper Input Validation
ghsa·2017-10-24
CVE-2013-1854 [MEDIUM] CWE-20 Active Record Improper Input Validation
Active Record Improper Input Validation
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.
OSV
CVE-2013-1854: The Active Record component in Ruby on Rails 2
osv·2013-03-19·CVSS 5.0
CVE-2013-1854 [MEDIUM] CVE-2013-1854: The Active Record component in Ruby on Rails 2
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability [epel-5]
bugzilla·2013-03-21·CVSS 5.0
CVE-2013-1854 [MEDIUM] CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability [epel-5]
CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking
Bugzilla
CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability [fedora-18]
bugzilla·2013-03-21·CVSS 5.0
CVE-2013-1854 [MEDIUM] CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability [fedora-18]
CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-18 tracking
Bugzilla
CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability
bugzilla·2013-03-14·CVSS 5.0
CVE-2013-1854 [MEDIUM] CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability
CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability
Symbol DoS vulnerability in Active Record
There is a symbol DoS vulnerability in Active Record. This vulnerability has been assigned the CVE identifier CVE-2013-1854.
Versions Affected: 3.2.x, 3.1.x, 2.3.x
Not affected: 3.0.x
Fixed Versions: 3.2.13, 3.1.12
Impact
When a hash is provided as the find value for a query, the keys of the hash may be converted to symbols. In this example,
User.where(:name => { 'foo' => 'bar' })
the string 'foo' will be converted to a symbol. Impacted code will look something like this:
User.where(:name => params[:name])
Carefully crafted requests can coerce `params[:name]` to return a hash, and the keys to that hash may be converted to symbols.
All users running an affected relea
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2013/Oct/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00070.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00071.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00075.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00078.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00079.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0699.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1863.htmlhttp://support.apple.com/kb/HT5784http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/https://groups.google.com/group/ruby-security-ann/msg/34e0d780b04308de?dmode=source&output=gplainhttp://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2013/Oct/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00070.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00071.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00075.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00078.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00079.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0699.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1863.htmlhttp://support.apple.com/kb/HT5784http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/https://groups.google.com/group/ruby-security-ann/msg/34e0d780b04308de?dmode=source&output=gplain
2013-03-19
Published