CVE-2013-1856: Input Validation
The ActiveSupport::XmlMiniJDOM backend in lib/activesupport/xmlmini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.
Other sources
The ActiveSupport::XmlMiniJDOM backend in lib/activesupport/xmlmini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1856?
CVE-2013-1856 is classified as a moderate severity vulnerability due to improper restrictions in the XML parser.
How do I fix CVE-2013-1856?
To fix CVE-2013-1856, upgrade the ActiveSupport gem to version 3.1.12 or higher for Rails 3.1.x and to version 3.2.13 or higher for Rails 3.2.x.
Which versions are affected by CVE-2013-1856?
CVE-2013-1856 affects Ruby on Rails versions 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 when using JRuby.
What components are involved in CVE-2013-1856?
CVE-2013-1856 involves the ActiveSupport::XmlMini_JDOM backend from the Active Support component in Ruby on Rails.
Are there any known exploits for CVE-2013-1856?
There are no public details available regarding specific exploits that target CVE-2013-1856.