← Back

CVE-2013-1856

nvd nist
Published: Mar 19, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:P
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.

Affected (47)

2 products
Rails
Ruby On Rails
Configuration A
47 vulnerable
Vulnerable SoftwareAffected Versions
Rubyonrails
Version 3.1.0
Version 3.1.0 beta1
Version 3.1.0 rc1
Version 3.1.0 rc2
Version 3.1.0 rc3
Version 3.1.0 rc4
Version 3.1.0 rc5
Version 3.1.0 rc6
Version 3.1.0 rc7
Version 3.1.0 rc8
Version 3.1.10
Version 3.1.1
Version 3.1.1 rc1
Version 3.1.1 rc2
Version 3.1.1 rc3
Version 3.1.2
Version 3.1.2 rc1
Version 3.1.2 rc2
Version 3.1.3
Version 3.1.4
Version 3.1.4 rc1
Version 3.1.5
Version 3.1.5 rc1
Version 3.1.6
Version 3.1.7
Version 3.1.8
Version 3.1.9
Version 3.2.0
Version 3.2.0 rc1
Version 3.2.0 rc2
Version 3.2.10
Version 3.2.11
Version 3.2.12
Version 3.2.1
Version 3.2.2
Version 3.2.2 rc1
Version 3.2.3
Version 3.2.3 rc1
Version 3.2.3 rc2
Version 3.2.4
Version 3.2.4 rc1
Version 3.2.5
Version 3.2.6
Version 3.2.7
Version 3.2.8
Version 3.2.9
Version 3.1.11

Timeline

No history available yet.