AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-1856

MEDIUM · CVSS 5.8 EPSS 2.05%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2013-03-19 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2013-1856
Severity
MEDIUM
CVSS
5.8
EPSS
2.05%

Original NVD Description

The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.