CVE-2013-1854
Summary
| CVE | CVE-2013-1854 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-03-19 22:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.0 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.1 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.10 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.11 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.12 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.13 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.14 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.15 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.16 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.2 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.3 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.4 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.9 | All | All | All |
| Application | Rubyonrails | Rails | 3.1.0 | All | All | All |
| Application | Rubyonrails | Rails | 3.1.0 | beta1 | All | All |
| Application | Rubyonrails | Rails | 3.1.0 | rc1 | All | All |
| Application | Rubyonrails | Rails | 3.1.0 | rc2 | All | All |
| Application | Rubyonrails | Rails | 3.1.0 | rc3 | All | All |
| Application | Rubyonrails | Rails | 3.1.0 | rc4 | All | All |
| Application | Rubyonrails | Rails | 3.1.0 | rc5 | All | All |
| Application | Rubyonrails | Rails | 3.1.0 | rc6 | All | All |
| Application | Rubyonrails | Rails | 3.1.0 | rc7 | All | All |
| Application | Rubyonrails | Rails | 3.1.0 | rc8 | All | All |
| Application | Rubyonrails | Rails | 3.1.1 | All | All | All |
| Application | Rubyonrails | Rails | 3.1.1 | rc1 | All | All |
| Application | Rubyonrails | Rails | 3.1.1 | rc2 | All | All |
| Application | Rubyonrails | Rails | 3.1.1 | rc3 | All | All |
| Application | Rubyonrails | Rails | 3.1.10 | All | All | All |
| Application | Rubyonrails | Rails | 3.1.2 | All | All | All |
| Application | Rubyonrails | Rails | 3.1.2 | rc1 | All | All |
| Application | Rubyonrails | Rails | 3.1.2 | rc2 | All | All |
| Application | Rubyonrails | Rails | 3.1.3 | All | All | All |
| Application | Rubyonrails | Rails | 3.1.4 | All | All | All |
| Application | Rubyonrails | Rails | 3.1.4 | rc1 | All | All |
| Application | Rubyonrails | Rails | 3.1.5 | All | All | All |
| Application | Rubyonrails | Rails | 3.1.5 | rc1 | All | All |
| Application | Rubyonrails | Rails | 3.1.6 | All | All | All |
| Application | Rubyonrails | Rails | 3.1.7 | All | All | All |
| Application | Rubyonrails | Rails | 3.1.8 | All | All | All |
| Application | Rubyonrails | Rails | 3.1.9 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.0 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.0 | rc1 | All | All |
| Application | Rubyonrails | Rails | 3.2.0 | rc2 | All | All |
| Application | Rubyonrails | Rails | 3.2.1 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.10 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.11 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.12 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.2 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.2 | rc1 | All | All |
| Application | Rubyonrails | Rails | 3.2.3 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.3 | rc1 | All | All |
| Application | Rubyonrails | Rails | 3.2.3 | rc2 | All | All |
| Application | Rubyonrails | Rails | 3.2.4 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.4 | rc1 | All | All |
| Application | Rubyonrails | Rails | 3.2.5 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.6 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.7 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.8 | All | All | All |
| Application | Rubyonrails | Rails | 3.2.9 | All | All | All |
| Application | Rubyonrails | Ruby On Rails | 2.3.17 | All | All | All |
| Application | Rubyonrails | Ruby On Rails | 3.1.11 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Google Groups | af854a3a-2127-422b-91ae-364da2661108 | groups.google.com | |
| About the security content of OS X Mountain Lion v10.8.4 and Security Update 2013-002 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| openSUSE-SU-2013:0659-1: moderate: update for rubygem-activerecord-3_2 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2013:0660-1: moderate: update for rubygem-activerecord-2_3 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| APPLE-SA-2013-06-04-1 OS X Mountain Lion v10.8.4 and Security Update 2013-002 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| openSUSE-SU-2013:0664-1: moderate: update for rubygem-activesupport-2_3 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| APPLE-SA-2013-10-22-5 OS X Server 3.0 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| openSUSE-SU-2013:0668-1: moderate: update for rubygem-activesupport-2_3 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Riding Rails: [SEC] [ANN] Rails 3.2.13, 3.1.12, and 2.3.18 have been released! | af854a3a-2127-422b-91ae-364da2661108 | weblog.rubyonrails.org | |
| openSUSE-SU-2013:0667-1: moderate: update for rubygem-activerecord-2_3 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| access.redhat.com | CVE-2013-1854 | MITRE | access.redhat.com | |
| 921329 – (CVE-2013-1854) CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.