multi_xml
Provides swappable XML backends utilizing LibXML, Nokogiri, Ox, or REXML.
Activity
- Latest release
- 4mo ago
- Total releases
- 29
- Cadence
- ~28 days
- Last 12 months
- 4
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Oct 02, 2010
| Version | Released | |
|---|---|---|
0.9.1
patch
| ||
0.9.0
minor
| ||
0.8.1
patch
| ||
0.8.0
minor
| ||
0.7.2
patch
| ||
0.7.1
patch
| ||
0.7.0
minor
| ||
0.6.0
minor
| ||
0.5.5
patch
| ||
0.5.4
patch
| ||
0.5.3
patch
| ||
0.5.2
patch
| ||
0.5.1
patch
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.4.4
patch
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.4.3
patch
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.4.2
patch
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.2.2
patch
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.2.1
patch
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.1.4
patch
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.1.3
patch
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.1.1
patch
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.1.2
patch
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.1.0
minor
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev | ||
0.0.1
initial
1 CVE
CVE-2013-0175
GHSA-pchc-949f-53m5
Oct 24, 2017
Improper Input Validation in multi_xml
High
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
0.3.0
0.4.0
0.4.1
+ 5 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
Fixed in
0.5.2
References
Updated Dec 04, 2024 · Source: OSV.dev |