Lucene search

K
cve[email protected]CVE-2013-1801
HistoryApr 09, 2013 - 8:55 p.m.

CVE-2013-1801

2013-04-0920:55:01
CWE-264
web.nvd.nist.gov
72
cve-2013-1801
httparty gem
ruby
object-injection attacks
arbitrary code
denial of service
memory consumption
cpu consumption
yaml type conversion
vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.6 High

AI Score

Confidence

High

0.973 High

EPSS

Percentile

99.9%

The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156.

Affected configurations

NVD
Node
john_nunemakerhttpartyRange0.9.0
OR
john_nunemakerhttpartyMatch0.1.0
OR
john_nunemakerhttpartyMatch0.1.1
OR
john_nunemakerhttpartyMatch0.1.2
OR
john_nunemakerhttpartyMatch0.1.3
OR
john_nunemakerhttpartyMatch0.1.5
OR
john_nunemakerhttpartyMatch0.1.6
OR
john_nunemakerhttpartyMatch0.1.7
OR
john_nunemakerhttpartyMatch0.1.8
OR
john_nunemakerhttpartyMatch0.2.0
OR
john_nunemakerhttpartyMatch0.2.1
OR
john_nunemakerhttpartyMatch0.2.2
OR
john_nunemakerhttpartyMatch0.2.3
OR
john_nunemakerhttpartyMatch0.2.4
OR
john_nunemakerhttpartyMatch0.2.5
OR
john_nunemakerhttpartyMatch0.2.6
OR
john_nunemakerhttpartyMatch0.2.7
OR
john_nunemakerhttpartyMatch0.2.8
OR
john_nunemakerhttpartyMatch0.2.9
OR
john_nunemakerhttpartyMatch0.2.10
OR
john_nunemakerhttpartyMatch0.3.0
OR
john_nunemakerhttpartyMatch0.3.1
OR
john_nunemakerhttpartyMatch0.4.0
OR
john_nunemakerhttpartyMatch0.4.1
OR
john_nunemakerhttpartyMatch0.4.2
OR
john_nunemakerhttpartyMatch0.4.3
OR
john_nunemakerhttpartyMatch0.4.4
OR
john_nunemakerhttpartyMatch0.4.5
OR
john_nunemakerhttpartyMatch0.5.0
OR
john_nunemakerhttpartyMatch0.5.1
OR
john_nunemakerhttpartyMatch0.5.2
OR
john_nunemakerhttpartyMatch0.6.0
OR
john_nunemakerhttpartyMatch0.6.1
OR
john_nunemakerhttpartyMatch0.7.0
OR
john_nunemakerhttpartyMatch0.7.1
OR
john_nunemakerhttpartyMatch0.7.2
OR
john_nunemakerhttpartyMatch0.7.3
OR
john_nunemakerhttpartyMatch0.7.4
OR
john_nunemakerhttpartyMatch0.7.5
OR
john_nunemakerhttpartyMatch0.7.6
OR
john_nunemakerhttpartyMatch0.7.7
OR
john_nunemakerhttpartyMatch0.7.8
OR
john_nunemakerhttpartyMatch0.8.0
OR
john_nunemakerhttpartyMatch0.8.1
OR
john_nunemakerhttpartyMatch0.8.2
OR
john_nunemakerhttpartyMatch0.8.3

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.6 High

AI Score

Confidence

High

0.973 High

EPSS

Percentile

99.9%