CVE-2013-1801 Information
Feb 14, 2021
cve
Description
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values which might allow remote attackers to conduct object-injection attacks and execute arbitrary code or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion a similar vulnerability to CVE-2013-0156.
Reference
http://www.securityfocus.com/bid/58260 https://bugzilla.redhat.com/show_bug.cgi?id=917229 https://github.com/jnunemaker/httparty/commit/53a812426dd32108d6cba4272b493aa03bc8c031 https://support.cloud.engineyard.com/entries/22915701-january-14-2013-security-vulnerabilities-httparty-extlib-crack-nori-update-these-gems-immediately
Share on: