CVE-2013-0333
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct SQL injection attacks, or bypass authentication via crafted data that triggers unsafe decoding, a different vulnerability than CVE-2013-0156.
- Affected products
- Ruby On Rails, Suse
- Rubyonrails Rails
- = 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.9, 2.3.10, 2.3.11, 2.3.12, 2.3.13, 2.3.14, 2.3.15
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 95.3% (100th percentile)
- NVD status
- Modified
- Published
- 2013-01-30
CVE-2013-0333 at NVD
9 known exploits for CVE-2013-0333
Proof-of-concept code and exploit modules indexed by Sploitus
heroku-CVE-2013-0333
heroku-CVE-2013-0156
Ruby On Rails JSON Processor YAML Deserialization Scanner
Ruby on Rails JSON Processor YAML Deserialization Scanner
Ruby on Rails JSON Processor YAML Deserialization Code Execution
Ruby on Rails 'convert_json_to_yaml()'方法安全漏洞
Ruby on Rails - JSON Processor YAML Deserialization Code Execution (Metasploit)
Ruby on Rails JSON Processor YAML Deserialization Code Execution
Ruby on Rails JSON Processor YAML Deserialization Code Execution