Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-1854
HistoryMar 19, 2013 - 10:55 p.m.

Design/Logic Flaw

2013-03-1922:55:00
PRIOn knowledge base
www.prio-n.com
18

6.9 Medium

AI Score

Confidence

High

0.089 Low

EPSS

Percentile

94.6%

The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.