CERT-In Vulnerability Note
CIVN-2013-0223
Multiple Vulnerabilities in Ruby on Rails
Original Issue Date:December 17, 2013
Severity Rating: MEDIUM
Systems Affected
- Ruby on Rails version 3.x prior to 3.2.16.
- Ruby on Rails version 4.0.0, 4.0.1.
Overview
Multiple vulnerabilities have been reported in Ruby on Rails which could allow a remote attackers to execute malicious packet on the network , cause cross-site scripting and denial of service condition.
Description
Multiple vulnerabilities exist in Ruby on Rails due to improper validation of users input. A remote attacker can exploit these vulnerabilities by enticing the users browser to execute specially crafted arbitrary data .
Successful exploitation of these vulnerabilities could allow the attacker to access the target users cookies, access data submitted by the target user to the site via web form, authenticate the attacker to act on the site on behalf of the target user.
Workaround
- Repl ace the standard i18n exception handler with a fixed one
Solution
Install appropriate security fixes as suggested in vendors advisory
http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/
Vendor Information
Ruby On Rails
http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/
References
Security Tracker
http://securitytracker.com/id/1029420
Secunia
http://secunia.com/advisories/cve_reference/CVE-2013-6414/
http://secunia.com/advisories/cve_reference/CVE-2013-6415/
http://secunia.com/advisories/cve_reference/CVE-2013-6416/
http://secunia.com/advisories/cve_reference/CVE-2013-6417/
http://secunia.com/advisories/cve_reference/CVE-2013-4491/
http://secunia.com/advisories/cve_reference/CVE-2013-4492/
Security Focus
http://www.securityfocus.com/bid/64076
http://www.securityfocus.com/bid/64074
http://www.securityfocus.com/bid/64077
http://www.securityfocus.com/bid/64071
http://www.securityfocus.com/bid/64106
CVE Name
CVE-2013-4491
CVE-2013-4492
CVE-2013-6414
CVE-2013-6415
CVE-2013-6416
CVE-2013-6417
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|