CVE-2015-3227

Ruby on Rails <4.1.11 & <4.2.2 - DoS

Title source: llm
STIX 2.1

Description

The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033755
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75234
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2015-07/msg00050.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3464
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2015/06/16/16

Scores

EPSS 0.0268
EPSS Percentile 86.0%

Details

Status published
Products (14)
opensuse/opensuse 13.1
opensuse/opensuse 13.2
rubygems/activesupport 4.0.0.beta1 - 4.1.11RubyGems
rubyonrails/rails 4.1.0
rubyonrails/rails 4.1.1
rubyonrails/rails 4.1.2
rubyonrails/rails 4.1.3
rubyonrails/rails 4.1.4
rubyonrails/rails 4.1.5
rubyonrails/rails 4.1.6
... and 4 more
Published Jul 26, 2015
Tracked Since Feb 18, 2026