CVE-2013-1801

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
09/04/2013
Last modified:
10/04/2013

Description

The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:john_nunemaker:httparty:*:*:*:*:*:*:*:* 0.9.0 (including)
cpe:2.3:a:john_nunemaker:httparty:0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.1.2:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.1.3:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.1.5:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.1.6:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.1.7:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.1.8:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.2.2:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.2.3:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.2.4:*:*:*:*:*:*:*
cpe:2.3:a:john_nunemaker:httparty:0.2.5:*:*:*:*:*:*:*