CVE-2015-3227
Summary
| CVE | CVE-2015-3227 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-07-26 22:59:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.2 | All | All | All |
| Application | Rubyonrails | Rails | 4.1.0 | All | All | All |
| Application | Rubyonrails | Rails | 4.1.1 | All | All | All |
| Application | Rubyonrails | Rails | 4.1.2 | All | All | All |
| Application | Rubyonrails | Rails | 4.1.3 | All | All | All |
| Application | Rubyonrails | Rails | 4.1.4 | All | All | All |
| Application | Rubyonrails | Rails | 4.1.5 | All | All | All |
| Application | Rubyonrails | Rails | 4.1.6 | All | All | All |
| Application | Rubyonrails | Rails | 4.1.7 | All | All | All |
| Application | Rubyonrails | Rails | 4.1.8 | All | All | All |
| Application | Rubyonrails | Rails | 4.2.0 | All | All | All |
| Application | Rubyonrails | Rails | 4.2.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3464-1 rails | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| groups.google.com/forum/message/raw | af854a3a-2127-422b-91ae-364da2661108 | groups.google.com | Vendor Advisory |
| openSUSE-SU-2015:1279-1: moderate: Security update for rubygem-activesup | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Ruby on Rails activesupport CVE-2015-3227 XML Parsing Remote Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Rails Bugs Let Remote Users Deny Service and Conduct Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| oss-security - [CVE-2015-3227] Possible Denial of Service attack in Active Support | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.