VDB
Sign up
MEDIUM

GHSA-j96r-xvjq-r9pg

activesupport vulnerable to Denial of Service via large XML document depth

Quick fix

GHSA-j96r-xvjq-r9pg — activesupport: upgrade to the fixed version with the command below.

bundle update activesupport

Details

The (1) `jdom.rb` and (2) `rexml.rb` components in Active Support in Ruby on Rails before 3.2.22, 4.1.x before 4.1.11, and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activesupport
Introduced in: 4.0.0.beta1Fixed in: 4.1.11
Fixbundle update activesupport
RubyGems/activesupport
Introduced in: 4.2.0.beta1Fixed in: 4.2.2
Fixbundle update activesupport
RubyGems/activesupport
Introduced in: 0Fixed in: 3.2.22
Fixbundle update activesupport

References