RHSA-2013:0153: Critical: Ruby on Rails security update
Ruby on Rails is a model–view–controller (MVC) framework for webapplication development. Action Pack implements the controller and the viewcomponents. Active Support provides support and utility classes used by theRuby on Rails framework.Multiple flaws were found in the way Ruby on Rails performed XML parameterparsing in HTTP requests. A remote attacker could use these flaws toexecute arbitrary code with the privileges of a Ruby on Rails application,perform SQL injection attacks, or bypass the authentication using aspecially-created HTTP request. (CVE-2013-0156)Red Hat is aware that a public exploit for the CVE-2013-0156 issues isavailable that allows remote code execution in applications using Ruby onRails.All users of Red Hat OpenShift Enterprise are advised to upgrade to theseupdated packages, which correct these issues. For Red Hat OpenShiftEnterprise administrators, the openshift-broker and openshift-consoleservices must be restarted for this update to take effect. Users ofOpenShift are advised to update their own applications that are runningRuby on Rails.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2013:0153?
The severity of RHSA-2013:0153 is classified as critical.
How do I fix RHSA-2013:0153?
To fix RHSA-2013:0153, update the affected Ruby on Rails packages to the specified remedied versions listed in the advisory.
What systems are affected by RHSA-2013:0153?
RHSA-2013:0153 affects multiple Ruby on Rails packages, including actionpack and activesupport for specific versions.
What vulnerabilities were addressed in RHSA-2013:0153?
RHSA-2013:0153 addresses multiple flaws found in the Ruby on Rails framework that could potentially lead to security issues.
Is there a risk of data compromise with RHSA-2013:0153?
Yes, the vulnerabilities addressed in RHSA-2013:0153 pose a risk of data compromise if not remediated.