Vulnerability Intelligence Report
CVE-2013-0277
ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:7.50%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| rubyonrails | rails | 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, 3.0.12, 3.0.13, 3.0.14, 3.0.16, 3.0.17, 3.0.18, 3.0.19, 3.0.20, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.9, 2.3.10, 2.3.11, 2.3.12, 2.3.13, 2.3.14, 2.3.15, 2.3.16 |
| rubyonrails | ruby_on_rails | 3.0.4 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
7.497%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2012-12-06T00:00:00 |
| Published | 2013-02-13T01:00:00 |
| Patch Date | 2013-02-11 |
| Last Updated | 2024-08-06T14:18:09 |
Community Chatter & Buzz