|
|
| |
|
| |
rubygem-activesupport: multiple vulnerabilities
| Package(s): | rubygem-activesupport |
CVE #(s): | CVE-2013-0333
|
| Created: | January 29, 2013 |
Updated: | February 10, 2013 |
| Description: |
From the Red Hat advisory:
A flaw was found in the way Active Support performed the parsing of JSON
requests by translating them to YAML. A remote attacker could use this flaw
to execute arbitrary code with the privileges of a Ruby on Rails
application, perform SQL injection attacks, or bypass the authentication
using a specially-created JSON request. |
| Alerts: |
|
( Log in to post comments)
|
|
|