// For flags

CVE-2013-0175

openSUSE Security Advisory - openSUSE-SU-2025:15122-1

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

multi_xml v0.5.2 de Ruby, tal como se utiliza en Grape antes de v0.2.6 y posiblemente otros productos, no restringe debidamente vaciados de valores de cadena, lo que permite a atacantes remotos realizar ataques de inyección a objetos y ejecutar código arbitrario o causar una denegación de servicio (consumo de memoria y CPU) que implica anidadas referencias de entidad XML, mediante el aprovechamiento de apoyo (1) YAML conversión de tipo o (2) la conversión de tipos Symbol, una vulnerabilidad similar a CVE-2013-0156.

These are all security issues fixed in the ruby3.4-rubygem-multi_xml-0.6.0-1.29 package on the GA media of openSUSE Tumbleweed.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-12-06 CVE Reserved
  • 2013-04-25 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Erik Michaels-ober
Search vendor "Erik Michaels-ober"
Multi Xml
Search vendor "Erik Michaels-ober" for product "Multi Xml"
0.5.2
Search vendor "Erik Michaels-ober" for product "Multi Xml" and version "0.5.2"
-
Affected
in Ruby-lang
Search vendor "Ruby-lang"
Ruby
Search vendor "Ruby-lang" for product "Ruby"
*-
Safe
Erik Michaels-ober
Search vendor "Erik Michaels-ober"
Multi Xml
Search vendor "Erik Michaels-ober" for product "Multi Xml"
0.5.2
Search vendor "Erik Michaels-ober" for product "Multi Xml" and version "0.5.2"
-
Affected
Grape Project
Search vendor "Grape Project"
Grape
Search vendor "Grape Project" for product "Grape"
0.1.0
Search vendor "Grape Project" for product "Grape" and version "0.1.0"
-
Affected
Grape Project
Search vendor "Grape Project"
Grape
Search vendor "Grape Project" for product "Grape"
0.1.1
Search vendor "Grape Project" for product "Grape" and version "0.1.1"
-
Affected
Grape Project
Search vendor "Grape Project"
Grape
Search vendor "Grape Project" for product "Grape"
0.1.2
Search vendor "Grape Project" for product "Grape" and version "0.1.2"
-
Affected
Grape Project
Search vendor "Grape Project"
Grape
Search vendor "Grape Project" for product "Grape"
0.1.3
Search vendor "Grape Project" for product "Grape" and version "0.1.3"
-
Affected
Grape Project
Search vendor "Grape Project"
Grape
Search vendor "Grape Project" for product "Grape"
0.1.4
Search vendor "Grape Project" for product "Grape" and version "0.1.4"
-
Affected
Grape Project
Search vendor "Grape Project"
Grape
Search vendor "Grape Project" for product "Grape"
0.1.5
Search vendor "Grape Project" for product "Grape" and version "0.1.5"
-
Affected
Grape Project
Search vendor "Grape Project"
Grape
Search vendor "Grape Project" for product "Grape"
0.2.0
Search vendor "Grape Project" for product "Grape" and version "0.2.0"
-
Affected
Grape Project
Search vendor "Grape Project"
Grape
Search vendor "Grape Project" for product "Grape"
0.2.1
Search vendor "Grape Project" for product "Grape" and version "0.2.1"
-
Affected
Grape Project
Search vendor "Grape Project"
Grape
Search vendor "Grape Project" for product "Grape"
0.2.2
Search vendor "Grape Project" for product "Grape" and version "0.2.2"
-
Affected
Grape Project
Search vendor "Grape Project"
Grape
Search vendor "Grape Project" for product "Grape"
0.2.3
Search vendor "Grape Project" for product "Grape" and version "0.2.3"
-
Affected
Grape Project
Search vendor "Grape Project"
Grape
Search vendor "Grape Project" for product "Grape"
0.2.4
Search vendor "Grape Project" for product "Grape" and version "0.2.4"
-
Affected
Grape Project
Search vendor "Grape Project"
Grape
Search vendor "Grape Project" for product "Grape"
0.2.5
Search vendor "Grape Project" for product "Grape" and version "0.2.5"
-
Affected