VDB
KO
MEDIUM

GHSA-j96r-xvjq-r9pg

activesupport vulnerable to Denial of Service via large XML document depth

Details

The (1) `jdom.rb` and (2) `rexml.rb` components in Active Support in Ruby on Rails before 3.2.22, 4.1.x before 4.1.11, and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / activesupport
Introduced in: 4.0.0.beta1 Fixed in: 4.1.11
Fix bundle update activesupport
RubyGems / activesupport
Introduced in: 4.2.0.beta1 Fixed in: 4.2.2
Fix bundle update activesupport
RubyGems / activesupport
Introduced in: 0 Fixed in: 3.2.22
Fix bundle update activesupport

References