CVE-2015-3227
published 2015-07-26CVE-2015-3227: The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.26%
90.0th percentile
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | < rails 2:4.2.4-2 (bookworm) | rails 2:4.2.4-2 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | >= 0 < 2:4.2.4-2 | 2:4.2.4-2 |
| rubyonrails | rails | >= 0 < 2:4.2.4-2 | 2:4.2.4-2 |
| rubyonrails | rails | >= 0 < 2:4.2.4-2 | 2:4.2.4-2 |
| rubyonrails | rails | >= 0 < 2:4.2.4-2 | 2:4.2.4-2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
activesupport vulnerable to Denial of Service via large XML document depth
ghsa·2017-10-24
CVE-2015-3227 [MEDIUM] activesupport vulnerable to Denial of Service via large XML document depth
activesupport vulnerable to Denial of Service via large XML document depth
The (1) `jdom.rb` and (2) `rexml.rb` components in Active Support in Ruby on Rails before 3.2.22, 4.1.x before 4.1.11, and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
OSV
activesupport vulnerable to Denial of Service via large XML document depth
osv·2017-10-24
CVE-2015-3227 [MEDIUM] activesupport vulnerable to Denial of Service via large XML document depth
activesupport vulnerable to Denial of Service via large XML document depth
The (1) `jdom.rb` and (2) `rexml.rb` components in Active Support in Ruby on Rails before 3.2.22, 4.1.x before 4.1.11, and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
OSV
CVE-2015-3227: The (1) jdom
osv·2015-07-26·CVSS 5.0
CVE-2015-3227 [MEDIUM] CVE-2015-3227: The (1) jdom
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
Red Hat
rubygem-activesupport: Possible Denial of Service attack in Active Support in merge_element()
vendor_redhat·2015-06-16·CVSS 5.0
CVE-2015-3227 [MEDIUM] CWE-400 rubygem-activesupport: Possible Denial of Service attack in Active Support in merge_element()
rubygem-activesupport: Possible Denial of Service attack in Active Support in merge_element()
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
Package: ruby193-rubygem-activesupport (CloudForms Management Engine 5) - Will not fix
Package: rh-ror41-rubygem-activesupport (Red Hat Software Collections) - Will not fix
Package: ror40-rubygem-activesupport (Red Hat Software Collections) - Will not fix
Package: ruby193-rubygem-activesupport (Red Hat Software Collections) - Will not fix
Package: ruby193-rubygem-activesupport (Red Hat Subscription Asset Manager) - Will not fix
Package: rubygem
Debian
CVE-2015-3227: rails - The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails b...
vendor_debian·2015·CVSS 5.0
CVE-2015-3227 [MEDIUM] CVE-2015-3227: rails - The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails b...
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
Scope: local
bookworm: resolved (fixed in 2:4.2.4-2)
bullseye: resolved (fixed in 2:4.2.4-2)
forky: resolved (fixed in 2:4.2.4-2)
sid: resolved (fixed in 2:4.2.4-2)
trixie: resolved (fixed in 2:4.2.4-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3227 rubygem-activesupport: Possible Denial of Service attack in Active Support in merge_element() [fedora-all]
bugzilla·2015-07-31·CVSS 5.0
CVE-2015-3227 [MEDIUM] CVE-2015-3227 rubygem-activesupport: Possible Denial of Service attack in Active Support in merge_element() [fedora-all]
CVE-2015-3227 rubygem-activesupport: Possible Denial of Service attack in Active Support in merge_element() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this is
Bugzilla
CVE-2015-3227 rubygem-activesupport: Possible Denial of Service attack in Active Support in merge_element() [epel-all]
bugzilla·2015-07-31·CVSS 5.0
CVE-2015-3227 [MEDIUM] CVE-2015-3227 rubygem-activesupport: Possible Denial of Service attack in Active Support in merge_element() [epel-all]
CVE-2015-3227 rubygem-activesupport: Possible Denial of Service attack in Active Support in merge_element() [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2015-3227 rubygem-activesupport: Possible Denial of Service attack in Active Support in merge_element()
bugzilla·2015-06-16·CVSS 5.0
CVE-2015-3227 [MEDIUM] CVE-2015-3227 rubygem-activesupport: Possible Denial of Service attack in Active Support in merge_element()
CVE-2015-3227 rubygem-activesupport: Possible Denial of Service attack in Active Support in merge_element()
A possible denial of service attack in the XML processing in Active Support has been reported.
Specially crafted XML documents can cause applications to raise a
`SystemStackError` and potentially cause a denial of service attack. This
only impacts applications using REXML or JDOM as their XML processor. Other
XML processors that Rails supports are not impacted.
Workarounds
Use an XML parser that is not impacted by this problem, such as Nokogiri or
LibXML. You can change the processor like this:
ActiveSupport::XmlMini.backend = 'Nokogiri'
If you cannot change XML parsers, then adjust
`RUBY_THREAD_MACHINE_STACK_SIZE`.
Patches that fix this issue attached.
Acknowledgements:
Red
http://lists.opensuse.org/opensuse-updates/2015-07/msg00050.htmlhttp://openwall.com/lists/oss-security/2015/06/16/16http://www.debian.org/security/2016/dsa-3464http://www.securityfocus.com/bid/75234http://www.securitytracker.com/id/1033755https://groups.google.com/forum/message/raw?msg=rubyonrails-security/bahr2JLnxvk/x4EocXnHPp8Jhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00050.htmlhttp://openwall.com/lists/oss-security/2015/06/16/16http://www.debian.org/security/2016/dsa-3464http://www.securityfocus.com/bid/75234http://www.securitytracker.com/id/1033755https://groups.google.com/forum/message/raw?msg=rubyonrails-security/bahr2JLnxvk/x4EocXnHPp8J
2015-07-26
Published