The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2015-07-26T22:00:00

Updated: 2024-08-06T05:39:32.037Z

Reserved: 2015-04-10T00:00:00

Link: CVE-2015-3227

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2015-07-26T22:59:06.070

Modified: 2019-08-08T15:43:50.467

Link: CVE-2015-3227

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-06-16T00:00:00Z

Links: CVE-2015-3227 - Bugzilla