« Volver al listado

CVE-2007-5379

Estado: ModificadaMedia (5)—

Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash#from_xml) method, which uses XmlSimple (XML::Simple) unsafely, as demonstrated by reading passwords from the Pidgin (Gaim) .purple/accounts.xml file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-5379",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-10-19T23:17:00.000",
  "references": [
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=195315",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://dev.rubyonrails.org/ticket/8453",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://docs.info.apple.com/article.html?artnum=307179",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/40717",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/27657",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28136",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-200711-17.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://weblog.rubyonrails.org/2007/10/5/rails-1-2-4-maintenance-release",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/26096",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.us-cert.gov/cas/techalerts/TA07-352A.html",
      "tags": [
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/3508",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/4238",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=195315",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://dev.rubyonrails.org/ticket/8453",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://docs.info.apple.com/article.html?artnum=307179",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/40717",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/27657",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28136",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-200711-17.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://weblog.rubyonrails.org/2007/10/5/rails-1-2-4-maintenance-release",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/26096",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.us-cert.gov/cas/techalerts/TA07-352A.html",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/3508",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/4238",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the existence of arbitrary files and read arbitrary XML files via the Hash.from_xml (Hash#from_xml) method, which uses XmlSimple (XML::Simple) unsafely, as demonstrated by reading passwords from the Pidgin (Gaim) .purple/accounts.xml file."
    },
    {
      "lang": "es",
      "value": "El Rails anterior al 1.2.4, como el utilizado en el \"Ruby on Rails\", permite a atacantes remotos y a los servidores ActiveResource determinar la existencia de ficheros de su elección y leer ficheros XML de su elección a través del método Hash.from_xml (Hash#from_xml), el cual utiliza XmlSimple (XML::Simple) en modo no seguro, como lo demostrado leyendo las contraseñas del fichero Pidgin (Gaim) .purple/accounts.xml."
    }
  ],
  "lastModified": "2026-06-16T22:45:59.863",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:david_hansson:ruby_on_rails:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD060C44-C630-45BD-BFAD-74C8BFFBBD4E",
              "versionEndIncluding": "1.2.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}