nori
XML to Hash translator
Activity
- Latest release
- 2mo ago
- Total releases
- 28
- Cadence
- ~24 days
- Last 12 months
- 3
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Apr 29, 2011
| Version | Released | |
|---|---|---|
2.9.1
patch
| ||
2.9.0
minor
| ||
2.8.0
minor
| ||
2.7.1
patch
| ||
2.7.0
minor
| ||
2.6.0
minor
| ||
2.5.0
minor
| ||
2.4.0
minor
| ||
2.3.0
minor
| ||
2.2.0
minor
| ||
2.1.0
minor
| ||
1.1.5
patch
| ||
2.0.4
patch
| ||
1.0.3
patch
| ||
2.0.3
patch
| ||
1.1.4
patch
| ||
2.0.0
major
1 CVE
CVE-2013-0285
GHSA-4936-rj25-6wm6
Oct 24, 2017
nori contains Improper Input Validation
High
The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
2.0.0
1.1.0
1.1.2
1.1.3
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
1.1.4
2.0.2
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
1.1.3
patch
1 CVE
CVE-2013-0285
GHSA-4936-rj25-6wm6
Oct 24, 2017
nori contains Improper Input Validation
High
The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
2.0.0
1.1.0
1.1.2
1.1.3
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
1.1.4
2.0.2
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
1.1.2
patch
1 CVE
CVE-2013-0285
GHSA-4936-rj25-6wm6
Oct 24, 2017
nori contains Improper Input Validation
High
The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
2.0.0
1.1.0
1.1.2
1.1.3
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
1.1.4
2.0.2
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2013-0285
GHSA-4936-rj25-6wm6
Oct 24, 2017
nori contains Improper Input Validation
High
The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
2.0.0
1.1.0
1.1.2
1.1.3
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
1.1.4
2.0.2
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2013-0285
GHSA-4936-rj25-6wm6
Oct 24, 2017
nori contains Improper Input Validation
High
The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
2.0.0
1.1.0
1.1.2
1.1.3
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
1.1.4
2.0.2
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
0.2.4
patch
| ||
1.0.1
patch
1 CVE
CVE-2013-0285
GHSA-4936-rj25-6wm6
Oct 24, 2017
nori contains Improper Input Validation
High
The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
2.0.0
1.1.0
1.1.2
1.1.3
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
1.1.4
2.0.2
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2013-0285
GHSA-4936-rj25-6wm6
Oct 24, 2017
nori contains Improper Input Validation
High
The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. Affected versions
2.0.0
1.1.0
1.1.2
1.1.3
1.0.0
1.0.1
1.0.2
Fixed in
1.0.3
1.1.4
2.0.2
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
0.2.3
patch
| ||
0.2.2
patch
| ||
0.2.1
patch
| ||
0.2.0
initial
|