AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-0285

HIGH · CVSS 7.5 EPSS 2.31%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2013-04-09 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2013-0285
Severity
HIGH
CVSS
7.5
EPSS
2.31%

Original NVD Description

The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.