CVE-2013-1854: Red Hat Enterprise Linux

Medium severity, CVSS 5.0. EPSS: 3.5% chance of exploitation in the next 30 days.

The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.

Affected products

  • Red Hat Enterprise Linux: version 6.0 only
  • Rubyonrails Rails: version 2.3.0 only; version 2.3.1 only; version 2.3.2 only; version 2.3.3 only; version 2.3.4 only; version 2.3.9 only; …
  • Rubyonrails Ruby On Rails: version 2.3.17 only; version 3.1.11 only

Published 2013-03-19. Last modified 2026-06-16.