CVE-2013-1801

Jnunemaker Httparty < 0.9.0 - Access Control

Title source: rule
STIX 2.1

Description

The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156.

Scores

EPSS 0.0299
EPSS Percentile 86.6%

Details

CWE
CWE-264
Status published
Products (47)
jnunemaker/httparty 0.1.0
jnunemaker/httparty 0.1.1
jnunemaker/httparty 0.1.2
jnunemaker/httparty 0.1.3
jnunemaker/httparty 0.1.5
jnunemaker/httparty 0.1.6
jnunemaker/httparty 0.1.7
jnunemaker/httparty 0.1.8
jnunemaker/httparty 0.2.0
jnunemaker/httparty 0.2.1
... and 37 more
Published Apr 09, 2013
Tracked Since Feb 18, 2026