Web Hack List

Collected research

Aaron Patterson -- Serialized YAML Remote Code Execution

Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]

Rails security advisory for CVE-2013-0277. Active Record's serialize helper stores objects as YAML in a BLOB column, so any application letting users assign directly to a serialized attribute lets an attacker supply arbitrary YAML and reach denial of service or remote code execution. Fixed in 2.3.17, with attr_accessible given as the workaround for 3.0 and earlier.

Record

Document
Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]
Researcher
Aaron Patterson
Published by
Google Groups
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aaron Patterson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .