VDB
Sign up
CRITICAL

GHSA-fhj9-cjjh-27vm

Active Record contains deserialization of arbitrary YAML

Quick fix

GHSA-fhj9-cjjh-27vm — activerecord: upgrade to the fixed version with the command below.

bundle update activerecord

Details

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activerecord
Introduced in: 0Fixed in: 2.3.17
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 3.0.0Fixed in: 3.1.0
Fixbundle update activerecord

References