← Back

CVE-2013-0175

nvd nist
Published: Apr 25, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

Affected (13)

Multi Xml
1 product
Grape
Configuration A
1 platform
Running on/withPlatform Versions
Ruby Lang
Ruby
All versions
Configuration B
13 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.5.2
Grape Project
Version 0.1.0
Version 0.1.1
Version 0.1.2
Version 0.1.3
Version 0.1.4
Version 0.1.5
Version 0.2.0
Version 0.2.1
Version 0.2.2
Version 0.2.3
Version 0.2.4
Version 0.2.5

References (10)

Timeline

No history available yet.