CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
Percentile
87.3%
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on
Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled,
allow remote attackers to cause a denial of service (SystemStackError) via
a large XML document depth.
Author | Note |
---|---|
seth-arnold | in Oneiric-Saucy, rails package is just for transition |