webhat / oplerno

Marketplace for Oplerno
www.oplerno.com/
GNU General Public License v3.0
4 stars 5 forks source link

CVE-2015-3227 in activesupport #190

Open webhat opened 9 years ago

webhat commented 9 years ago

Security issue from Hakiri: There is a possible denial of service attack in the XML processing in Active Support. Specially crafted XML documents can cause applications to raise a SystemStackError and potentially cause a denial of service attack. This only impacts applications using REXML or JDOM as their XML processor. Other XML processors that Rails supports are not impacted.