Loading...
Loading...
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156.
April 9, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-1801
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.