Sha256: 7064f2e18f2fbec1b5897f5b0b0f5e6fece8e8be081149562737611ee80f5b34

Contents?: true

Size: 822 Bytes

Versions: 14

Compression:

Stored size: 822 Bytes

Contents

--- 
gem: activesupport
framework: rails
platform: jruby
cve: 2013-1856
osvdb: 91451
url: http://www.osvdb.org/show/osvdb/91451
title: XML Parsing Vulnerability affecting JRuby users
date: 2013-03-19

description: | 
 The ActiveSupport XML parsing functionality supports multiple
 pluggable backends. One backend supported for JRuby users is
 ActiveSupport::XmlMini_JDOM which makes use of the
 javax.xml.parsers.DocumentBuilder class. In some JVM configurations
 the default settings of that class can allow an attacker to construct
 XML which, when parsed, will contain the contents of arbitrary URLs
 including files from the application server. They may also allow for
 various denial of service attacks. Action Pack

cvss_v2: 7.8

unaffected_versions:
  - ~> 2.3.0

patched_versions:   
  - ~> 3.1.12
  - ">= 3.2.13"

Version data entries

14 entries across 14 versions & 3 rubygems

Version Path
bundler-budit-0.6.2 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
bundler-audit-0.6.1 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
bundler-audit-0.6.0 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
bundler-audit-0.5.0 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
bundler-audit-0.4.0 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
bundler-audit-0.3.1 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
mrjoy-bundler-audit-0.3.3 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
mrjoy-bundler-audit-0.3.2 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
mrjoy-bundler-audit-0.3.1 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
bundler-audit-0.3.0 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
mrjoy-bundler-audit-0.2.1 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
bundler-audit-0.2.0 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml
mrjoy-bundler-audit-0.1.4 data/ruby-advisory-db/gems/activesupport/OSVDB-91451.yml