suse · CVE-2013-0156

Quick triage

Priority: medium Published: 2021-05-30 13:08:04 UTC Updated: 2026-04-18 19:05:09 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2013-0156 severity moderate: SUSE including 21 source package names (ruby2.1-rubygem-extlib-0.9.16-1.1, ruby2.2-rubygem-extlib-0.9.16-7.4, …), 21 product×package rows across 5 product lines (SUSE Linux Enterprise Software Development Kit 11 SP2, SUSE Linux Enterprise Software Development Kit 11 SP4, … (5 product lines)): Fixed 21.

Description:

active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.

cvelogic Threat Intelligence