crack
Really simple JSON and XML parsing, ripped from Merb and Rails.
Activity
- Latest release
- 10mo ago
- Total releases
- 21
- Cadence
- ~4 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Apr 02, 2009
| Version | Released | |
|---|---|---|
1.0.1
patch
| ||
1.0.0
major
| ||
0.4.6
patch
| ||
0.4.5
patch
| ||
0.4.4
patch
| ||
0.4.3
patch
| ||
0.4.2
patch
| ||
0.4.1
patch
| ||
0.4.0
minor
| ||
0.3.2
patch
| ||
0.3.1
patch
1 CVE
CVE-2013-1800
GHSA-m7fq-cf8q-35q7
Oct 24, 2017
crack does not properly restrict casts of string values
High
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
Fixed in
0.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2013-1800
GHSA-m7fq-cf8q-35q7
Oct 24, 2017
crack does not properly restrict casts of string values
High
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
Fixed in
0.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2013-1800
GHSA-m7fq-cf8q-35q7
Oct 24, 2017
crack does not properly restrict casts of string values
High
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
Fixed in
0.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.1.8
patch
1 CVE
CVE-2013-1800
GHSA-m7fq-cf8q-35q7
Oct 24, 2017
crack does not properly restrict casts of string values
High
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
Fixed in
0.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.1.7
patch
1 CVE
CVE-2013-1800
GHSA-m7fq-cf8q-35q7
Oct 24, 2017
crack does not properly restrict casts of string values
High
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
Fixed in
0.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.1.6
patch
1 CVE
CVE-2013-1800
GHSA-m7fq-cf8q-35q7
Oct 24, 2017
crack does not properly restrict casts of string values
High
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
Fixed in
0.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.1.5
patch
1 CVE
CVE-2013-1800
GHSA-m7fq-cf8q-35q7
Oct 24, 2017
crack does not properly restrict casts of string values
High
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
Fixed in
0.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.1.4
patch
1 CVE
CVE-2013-1800
GHSA-m7fq-cf8q-35q7
Oct 24, 2017
crack does not properly restrict casts of string values
High
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
Fixed in
0.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.1.3
patch
1 CVE
CVE-2013-1800
GHSA-m7fq-cf8q-35q7
Oct 24, 2017
crack does not properly restrict casts of string values
High
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
Fixed in
0.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.1.2
patch
1 CVE
CVE-2013-1800
GHSA-m7fq-cf8q-35q7
Oct 24, 2017
crack does not properly restrict casts of string values
High
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
Fixed in
0.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.1.1
initial
1 CVE
CVE-2013-1800
GHSA-m7fq-cf8q-35q7
Oct 24, 2017
crack does not properly restrict casts of string values
High
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2.0
0.3.0
0.3.1
Fixed in
0.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev |