The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  Debian DLA | 
                DLA-603-1 | ruby-activesupport-3.2 security update | 
  Debian DSA | 
                DSA-3464-1 | rails security update | 
  EUVD | 
                EUVD-2017-0259 | activesupport vulnerable to Denial of Service via large XML document depth | 
  Github GHSA | 
                GHSA-j96r-xvjq-r9pg | activesupport vulnerable to Denial of Service via large XML document depth | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T05:39:32.037Z
Reserved: 2015-04-10T00:00:00
Link: CVE-2015-3227
No data.
Status : Deferred
Published: 2015-07-26T22:59:06.070
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-3227
                        OpenCVE Enrichment
                    No data.
 Debian DLA
 Debian DSA
 EUVD
 Github GHSA