High severityNVD Advisory· Published Apr 9, 2013· Updated Jun 16, 2026
CVE-2013-0285
CVE-2013-0285
Description
The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
noriRubyGems | >= 2.0.0, < 2.0.2 | 2.0.2 |
noriRubyGems | >= 1.1.0, < 1.1.4 | 1.1.4 |
noriRubyGems | >= 1.0.0, < 1.0.3 | 1.0.3 |
Affected products
10cpe:2.3:a:nori_gem_project:nori_gem:2.0.0:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:nori_gem_project:nori_gem:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:nori_gem_project:nori_gem:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:nori_gem_project:nori_gem:1.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:nori_gem_project:nori_gem:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:nori_gem_project:nori_gem:1.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:nori_gem_project:nori_gem:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:nori_gem_project:nori_gem:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:nori_gem_project:nori_gem:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:nori_gem_project:nori_gem:1.0.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
12- github.com/advisories/GHSA-4936-rj25-6wm6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-0285ghsaADVISORY
- seclists.org/oss-sec/2013/q1/304nvdWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/nori/CVE-2013-0285.ymlghsaWEB
- github.com/savonrb/nori/commit/2ca6f8603e406f884a8fcea6bc26f8f6bf168f40ghsaWEB
- github.com/savonrb/nori/commit/4bcf59abdcec6bcd1153241b122eda61a494e4fbghsaWEB
- github.com/savonrb/nori/commit/818f5263b1d597b603d46cbe1702cd2717259e32ghsaWEB
- github.com/savonrb/nori/commit/c3fdce7a2d2670b44f1cda35da0ae73cc1372084ghsaWEB
- github.com/savonrb/nori/commit/c5e07f5c32e615f0a4a7ee2782d37f7a33261be4ghsaWEB
- github.com/savonrb/nori/commit/d9b68667249b98776fb23ba9e9c548dc4b524709ghsaWEB
- web.archive.org/web/20130203232028/https://support.cloud.engineyard.com/entries/22915701-january-14-2013-security-vulnerabilities-httparty-extlib-crack-nori-update-these-gems-immediatelyghsaWEB
- support.cloud.engineyard.com/entries/22915701-january-14-2013-security-vulnerabilities-httparty-extlib-crack-nori-update-these-gems-immediatelynvd
News mentions
0No linked articles in our index yet.