RHSA-2013:0153: Critical: Ruby on Rails security update

Published Jan 10, 2013
·
Updated

Ruby on Rails is a model–view–controller (MVC) framework for webapplication development. Action Pack implements the controller and the viewcomponents. Active Support provides support and utility classes used by theRuby on Rails framework.Multiple flaws were found in the way Ruby on Rails performed XML parameterparsing in HTTP requests. A remote attacker could use these flaws toexecute arbitrary code with the privileges of a Ruby on Rails application,perform SQL injection attacks, or bypass the authentication using aspecially-created HTTP request. (CVE-2013-0156)Red Hat is aware that a public exploit for the CVE-2013-0156 issues isavailable that allows remote code execution in applications using Ruby onRails.All users of Red Hat OpenShift Enterprise are advised to upgrade to theseupdated packages, which correct these issues. For Red Hat OpenShiftEnterprise administrators, the openshift-broker and openshift-consoleservices must be restarted for this update to take effect. Users ofOpenShift are advised to update their own applications that are runningRuby on Rails.

Affected Software

7 affected componentsFixes available
redhat/ruby193-rubygem-actionpack<3.2.8-2.el6
3.2.8-2.el6
redhat/ruby193-rubygem-activesupport<3.2.8-3.el6
3.2.8-3.el6
redhat/rubygem-actionpack<3.0.13-2.1.el6
3.0.13-2.1.el6
redhat/rubygem-activesupport<3.0.13-2.el6
3.0.13-2.el6
redhat/ruby193-rubygem-actionpack<3.2.8-2.el6
3.2.8-2.el6
redhat/ruby193-rubygem-actionpack-doc<3.2.8-2.el6
3.2.8-2.el6
redhat/ruby193-rubygem-activesupport<3.2.8-3.el6
3.2.8-3.el6

Remediation

Event History

Jan 10, 2013
Advisory Published
12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2013:0153?

The severity of RHSA-2013:0153 is classified as critical.

2

How do I fix RHSA-2013:0153?

To fix RHSA-2013:0153, update the affected Ruby on Rails packages to the specified remedied versions listed in the advisory.

3

What systems are affected by RHSA-2013:0153?

RHSA-2013:0153 affects multiple Ruby on Rails packages, including actionpack and activesupport for specific versions.

4

What vulnerabilities were addressed in RHSA-2013:0153?

RHSA-2013:0153 addresses multiple flaws found in the Ruby on Rails framework that could potentially lead to security issues.

5

Is there a risk of data compromise with RHSA-2013:0153?

Yes, the vulnerabilities addressed in RHSA-2013:0153 pose a risk of data compromise if not remediated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203