Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW03ZnEtY2Y4cS0zNXE3

crack does not properly restrict casts of string values

The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

Permalink: https://github.com/advisories/GHSA-m7fq-cf8q-35q7
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW03ZnEtY2Y4cS0zNXE3
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 7 years ago
Updated: about 1 year ago


EPSS Percentage: 0.14031
EPSS Percentile: 0.95647

Identifiers: GHSA-m7fq-cf8q-35q7, CVE-2013-1800
References: Repository: https://github.com/jnunemaker/crack
Blast Radius: 0.0

Affected Packages

rubygems:crack
Dependent packages: 310
Dependent repositories: 47,847
Downloads: 288,082,472 total
Affected Version Ranges: < 0.3.2
Fixed in: 0.3.2
All affected versions: 0.1.1, 0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.1.7, 0.1.8, 0.2.0, 0.3.0, 0.3.1
All unaffected versions: 0.3.2, 0.4.0, 0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.4.5, 0.4.6, 1.0.0