CVE Vulnerabilities

CVE-2013-0277

Published: Feb 13, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
7.5 CRITICAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

Affected Software

NameVendorStart VersionEnd Version
RailsRubyonrails3.0.0 (including)3.0.0 (including)
RailsRubyonrails3.0.0-beta (including)3.0.0-beta (including)
RailsRubyonrails3.0.0-beta2 (including)3.0.0-beta2 (including)
RailsRubyonrails3.0.0-beta3 (including)3.0.0-beta3 (including)
RailsRubyonrails3.0.0-beta4 (including)3.0.0-beta4 (including)
RailsRubyonrails3.0.0-rc (including)3.0.0-rc (including)
RailsRubyonrails3.0.0-rc2 (including)3.0.0-rc2 (including)
RailsRubyonrails3.0.1 (including)3.0.1 (including)
RailsRubyonrails3.0.1-pre (including)3.0.1-pre (including)
RailsRubyonrails3.0.2 (including)3.0.2 (including)
RailsRubyonrails3.0.2-pre (including)3.0.2-pre (including)
RailsRubyonrails3.0.3 (including)3.0.3 (including)
RailsRubyonrails3.0.4-rc1 (including)3.0.4-rc1 (including)
RailsRubyonrails3.0.5 (including)3.0.5 (including)
RailsRubyonrails3.0.5-rc1 (including)3.0.5-rc1 (including)
RailsRubyonrails3.0.6 (including)3.0.6 (including)
RailsRubyonrails3.0.6-rc1 (including)3.0.6-rc1 (including)
RailsRubyonrails3.0.6-rc2 (including)3.0.6-rc2 (including)
RailsRubyonrails3.0.7 (including)3.0.7 (including)
RailsRubyonrails3.0.7-rc1 (including)3.0.7-rc1 (including)
RailsRubyonrails3.0.7-rc2 (including)3.0.7-rc2 (including)
RailsRubyonrails3.0.8 (including)3.0.8 (including)
RailsRubyonrails3.0.8-rc1 (including)3.0.8-rc1 (including)
RailsRubyonrails3.0.8-rc2 (including)3.0.8-rc2 (including)
RailsRubyonrails3.0.8-rc3 (including)3.0.8-rc3 (including)
RailsRubyonrails3.0.8-rc4 (including)3.0.8-rc4 (including)
RailsRubyonrails3.0.9 (including)3.0.9 (including)
RailsRubyonrails3.0.9-rc1 (including)3.0.9-rc1 (including)
RailsRubyonrails3.0.9-rc2 (including)3.0.9-rc2 (including)
RailsRubyonrails3.0.9-rc3 (including)3.0.9-rc3 (including)
RailsRubyonrails3.0.9-rc4 (including)3.0.9-rc4 (including)
RailsRubyonrails3.0.9-rc5 (including)3.0.9-rc5 (including)
RailsRubyonrails3.0.10 (including)3.0.10 (including)
RailsRubyonrails3.0.10-rc1 (including)3.0.10-rc1 (including)
RailsRubyonrails3.0.11 (including)3.0.11 (including)
RailsRubyonrails3.0.12 (including)3.0.12 (including)
RailsRubyonrails3.0.12-rc1 (including)3.0.12-rc1 (including)
RailsRubyonrails3.0.13 (including)3.0.13 (including)
RailsRubyonrails3.0.13-rc1 (including)3.0.13-rc1 (including)
RailsRubyonrails3.0.14 (including)3.0.14 (including)
RailsRubyonrails3.0.16 (including)3.0.16 (including)
RailsRubyonrails3.0.17 (including)3.0.17 (including)
RailsRubyonrails3.0.18 (including)3.0.18 (including)
RailsRubyonrails3.0.19 (including)3.0.19 (including)
RailsRubyonrails3.0.20 (including)3.0.20 (including)
Ruby_on_railsRubyonrails3.0.4 (including)3.0.4 (including)
RailsUbuntuhardy*
RailsUbuntulucid*
RailsUbuntuupstream*
Ruby-activerecord-2.3Ubuntuoneiric*
Ruby-activerecord-2.3Ubuntuprecise*
Ruby-activerecord-2.3Ubuntuquantal*
Ruby-activerecord-2.3Ubunturaring*
Ruby-activerecord-2.3Ubuntusaucy*
Ruby-activerecord-2.3Ubuntuupstream*

References