First published: Thu Jan 10 2013(Updated: )
Ruby on Rails is a model–view–controller (MVC) framework for web<br>application development. Action Pack implements the controller and the view<br>components. Active Support provides support and utility classes used by the<br>Ruby on Rails framework.<br>Multiple flaws were found in the way Ruby on Rails performed XML parameter<br>parsing in HTTP requests. A remote attacker could use these flaws to<br>execute arbitrary code with the privileges of a Ruby on Rails application,<br>perform SQL injection attacks, or bypass the authentication using a<br>specially-created HTTP request. (CVE-2013-0156)<br>Red Hat is aware that a public exploit for the CVE-2013-0156 issues is<br>available that allows remote code execution in applications using Ruby on<br>Rails.<br>All users of Red Hat OpenShift Enterprise are advised to upgrade to these<br>updated packages, which correct these issues. For Red Hat OpenShift<br>Enterprise administrators, the openshift-broker and openshift-console<br>services must be restarted for this update to take effect. Users of<br>OpenShift are advised to update their own applications that are running<br>Ruby on Rails.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ruby193-rubygem-actionpack | <3.2.8-2.el6 | 3.2.8-2.el6 |
redhat/ruby193-rubygem-activesupport | <3.2.8-3.el6 | 3.2.8-3.el6 |
redhat/rubygem-actionpack | <3.0.13-2.1.el6 | 3.0.13-2.1.el6 |
redhat/rubygem-activesupport | <3.0.13-2.el6 | 3.0.13-2.el6 |
redhat/ruby193-rubygem-actionpack | <3.2.8-2.el6 | 3.2.8-2.el6 |
redhat/ruby193-rubygem-actionpack-doc | <3.2.8-2.el6 | 3.2.8-2.el6 |
redhat/ruby193-rubygem-activesupport | <3.2.8-3.el6 | 3.2.8-3.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.