CVE-2013-1856
published 2013-03-19CVE-2013-1856: The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12…
PriorityP433medium5.8CVSS 2.0
AVNACMAuNCPINAP
EPSS
2.05%
79.4th percentile
The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
vendor_debian5.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
activesupport Improper Input Validation vulnerability
osv·2017-10-24
CVE-2013-1856 [MEDIUM] activesupport Improper Input Validation vulnerability
activesupport Improper Input Validation vulnerability
The `ActiveSupport::XmlMini_JDOM` backend in `lib/active_support/xml_mini/jdom.rb` in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.
GHSA
activesupport Improper Input Validation vulnerability
ghsa·2017-10-24
CVE-2013-1856 [MEDIUM] CWE-20 activesupport Improper Input Validation vulnerability
activesupport Improper Input Validation vulnerability
The `ActiveSupport::XmlMini_JDOM` backend in `lib/active_support/xml_mini/jdom.rb` in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.
Debian
CVE-2013-1856: rails - The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb i...
vendor_debian·2013·CVSS 5.8
CVE-2013-1856 [MEDIUM] CVE-2013-1856: rails - The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb i...
The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1856 rubygem-activesupport: jdom: XML Parsing Vulnerability affecting JRuby users [fedora-all]
bugzilla·2013-03-18·CVSS 5.8
CVE-2013-1856 [MEDIUM] CVE-2013-1856 rubygem-activesupport: jdom: XML Parsing Vulnerability affecting JRuby users [fedora-all]
CVE-2013-1856 rubygem-activesupport: jdom: XML Parsing Vulnerability affecting JRuby users [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
P
Bugzilla
CVE-2013-1856 rubygem-activesupport: jdom: XML Parsing Vulnerability affecting JRuby users
bugzilla·2013-03-14·CVSS 5.8
CVE-2013-1856 [MEDIUM] CVE-2013-1856 rubygem-activesupport: jdom: XML Parsing Vulnerability affecting JRuby users
CVE-2013-1856 rubygem-activesupport: jdom: XML Parsing Vulnerability affecting JRuby users
XML Parsing Vulnerability affecting JRuby users
There is a vulnerability in the JDOM backend to ActiveSupport's XML parser. This could allow an attacker to perform a denial of service attack or gain access to files stored on the application server. This vulnerability has been assigned the CVE identifier CVE-2013-1856.
Versions Affected: 3.0.0 and All Later Versions when using JRuby
Not affected: Applications not using JRuby or JRuby applications not using the JDOM backend.
Fixed Versions: 3.2.13, 3.1.12
Impact
The ActiveSupport XML parsing functionality supports multiple pluggable backends. One backend supported for JRuby users is ActiveSupport::XmlMini_JDOM which makes use of the javax.xml.parse
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2013/Oct/msg00006.htmlhttp://support.apple.com/kb/HT5784http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/https://groups.google.com/group/rubyonrails-security/msg/6c2482d4ed1545e6?dmode=source&output=gplainhttp://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2013/Oct/msg00006.htmlhttp://support.apple.com/kb/HT5784http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/https://groups.google.com/group/rubyonrails-security/msg/6c2482d4ed1545e6?dmode=source&output=gplain
2013-03-19
Published