CVE-2013-0175: multi_xml Gem for Ruby XML Parameter Parsing Remote Command Execution
(updated )
The multi_xml Gem for Ruby contains a flaw that is triggered when an error occurs during the parsing of XML parameters. With a crafted request containing arbitrary symbol and yaml types, a remote attacker can execute arbitrary commands.
References
Detect and mitigate CVE-2013-0175 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →