CVE-2013-0156 is a critical object-injection vulnerability in Ruby on Rails versions prior to 2.3.15, 3.0.19, 3.1.10, and 3.2.11, affecting the active_support/core_ext/hash/conversions.rb component. This flaw allows remote attackers to execute arbitrary code or cause a denial of service through improper string value casting, leveraging YAML or Symbol type conversion. With a CVSS score of 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P), it represents a high-severity risk, indicating that it can be exploited remotely with low complexity and without authentication, leading to partial confidentiality, integrity, and availability impacts. The vulnerability has known Metasploit modules for exploitation, including remote code execution, and has garnered significant community discussion and media coverage, with reports of active exploitation in the wild, such as the RubyMiner malware.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.2.0, < 3.2.11CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
< 2.3.15CPE matchmatch criteria | cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.0.19CPE matchmatch criteria | cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* | ||
>= 3.1.0, < 3.1.10CPE matchmatch criteria | cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.