datamapper/extlib

datamapper/extlib

Releases14
Frequency4 months 5 days
Last Release
Stars70
General Ruby extensions for Merb

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

The extlib gem 0.9.15 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.