Other nomination
Aaron Patterson -- Serialized YAML Remote Code Execution
Rails security advisory for CVE-2013-0277. Active Record's serialize helper stores objects as YAML in a BLOB column, so any application letting users assign directly to a serialized attribute lets an attacker supply arbitrary YAML and reach denial of service or remote code execution. Fixed in 2.3.17, with attr_accessible given as the workaround for 3.0 and earlier.
Record
- Researcher
- Aaron Patterson
- Published by
- Google Groups
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Aaron Patterson, first published at the original source. Preserved copies are kept so the citation survives its host.