Moderate severityNVD Advisory· Published Jul 26, 2015· Updated May 6, 2026
CVE-2015-3227
CVE-2015-3227
Description
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
activesupportRubyGems | >= 4.0.0.beta1, < 4.1.11 | 4.1.11 |
activesupportRubyGems | >= 4.2.0.beta1, < 4.2.2 | 4.2.2 |
activesupportRubyGems | < 3.2.22 | 3.2.22 |
Affected products
13cpe:2.3:a:rubyonrails:rails:4.1.0:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:rubyonrails:rails:4.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.2.1:*:*:*:*:*:*:*
Patches
312f763ce1131https://github.com/rails/railsvia ghsa
153cc843ad95https://github.com/rails/railsvia ghsa
78b29e08c700https://github.com/rails/railsvia ghsa
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
13- github.com/advisories/GHSA-j96r-xvjq-r9pgghsaADVISORY
- groups.google.com/forum/message/rawnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2015-3227ghsaADVISORY
- lists.opensuse.org/opensuse-updates/2015-07/msg00050.htmlnvdWEB
- openwall.com/lists/oss-security/2015/06/16/16nvdWEB
- www.debian.org/security/2016/dsa-3464nvdWEB
- github.com/rails/rails/commit/12f763ce1131d29d24bd0d8f868e2697a139aea3ghsaWEB
- github.com/rails/rails/commit/153cc843ad95930b00b0ca91d30b599b7dec9680ghsaWEB
- github.com/rails/rails/commit/78b29e08c700d889837af6c51c7debd3864abc3dghsaWEB
- web.archive.org/web/20200228041703/http://www.securityfocus.com/bid/75234ghsaWEB
- web.archive.org/web/20200517005133/http://www.securitytracker.com/id/1033755ghsaWEB
- www.securityfocus.com/bid/75234nvd
- www.securitytracker.com/id/1033755nvd
News mentions
0No linked articles in our index yet.