Collected research
Aaron Patterson -- Serialized YAML Remote Code Execution
Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]
Rails security advisory for CVE-2013-0277. Active Record's serialize helper stores objects as YAML in a BLOB column, so any application letting users assign directly to a serialized attribute lets an attacker supply arbitrary YAML and reach denial of service or remote code execution. Fixed in 2.3.17, with attr_accessible given as the workaround for 3.0 and earlier.
Record
- Document
- Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]
- Researcher
- Aaron Patterson
- Published by
- Google Groups
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Aaron Patterson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .