← Back

Grape Project

grape_project

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Grape
grape

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Erik Michaels Ober
Grape Project
2Grape
Multi Xml
Apr 29, 2026
Apr 25, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute ar...Show more
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.Show less