CVE-2013-0277

critical
Published 2013-02-11 · Modified 2024-12-03
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-0277

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.openwall.com/lists/oss-security/2013/02/11/6

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.3.14.1
debian debianbullseyefixed2.3.14.1
debian debianforkyfixed2.3.14.1
debian debiansidfixed2.3.14.1
debian debiantrixiefixed2.3.14.1

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsactiverecord<~> 2.3.17~> 2.3.17
ruby RubyGemsactiverecord<2.3.172.3.17
ruby RubyGemsactiverecord>=3.0.0,<3.1.03.1.0

Application impact

VendorProductVersionsFixed
rubyonrailsrails3.0.0
rubyonrailsrails3.0.1
rubyonrailsrails3.0.2
rubyonrailsrails3.0.3
rubyonrailsrails3.0.4
rubyonrailsrails3.0.5
rubyonrailsrails3.0.6
rubyonrailsrails3.0.7
rubyonrailsrails3.0.8
rubyonrailsrails3.0.9
rubyonrailsrails3.0.10
rubyonrailsrails3.0.11
rubyonrailsrails3.0.12
rubyonrailsrails3.0.13
rubyonrailsrails3.0.14
rubyonrailsrails3.0.16
rubyonrailsrails3.0.17
rubyonrailsrails3.0.18
rubyonrailsrails3.0.19
rubyonrailsrails3.0.20
rubyonrailsruby_on_rails3.0.4
rubyonrailsrails2.3.0
rubyonrailsrails2.3.1
rubyonrailsrails2.3.2
rubyonrailsrails2.3.3
rubyonrailsrails2.3.4
rubyonrailsrails2.3.9
rubyonrailsrails2.3.10
rubyonrailsrails2.3.11
rubyonrailsrails2.3.12
rubyonrailsrails2.3.13
rubyonrailsrails2.3.14
rubyonrailsrails2.3.15
rubyonrailsrails2.3.16

References

Verify integrity in audit chain (admin only). AS-IS.