Lucene search

K
osvGoogleOSV:GHSA-FHJ9-CJJH-27VM
HistoryOct 24, 2017 - 6:33 p.m.

Active Record contains deserialization of arbitrary YAML

2017-10-2418:33:37
Google
osv.dev
18

0.099 Low

EPSS

Percentile

94.9%

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.