criticalREV. 01
CVE-2013-0156Ruby on Rails — Type Casting in Request Parsing to Code Execution
Rails converts structured request bodies into objects without restricting the types, so an unauthenticated request builds whatever the attacker names and runs code on the server.
Read the risk
THE VITAL STATS- CVSS score
- —/ 10 No score recorded
- EPSS probability
- 99% Likelihood of exploitation
- Attack complexity
- Low Conditions needed to exploit
- Known exploited
- Not listed
- CVE published
- 2013-01-13
- Exploit published
- Not recorded
- Confidence
- high
- Kill chain
- initial access
- MITRE ATT&CK
- T1190
- Severity
- critical
Attacker needsNetwork access to the application
Fixed inRails 2.3.15, Rails 3.0.19, Rails 3.1.10, Rails 3.2.11
Behind the card
5 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02Vendor advisoryweblog.rubyonrails.orgweblog.rubyonrails.org
- 03Writeupics-cert.us-cert.govics-cert.us-cert.gov
- 04Writeuplists.apple.comlists.apple.com
- 05Writeuprhn.redhat.comrhn.redhat.com
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| exploitation.attack_complexity, exploitation.exploit_available, references, published_at | nvd.nist.gov | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| epss | api.first.org | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisites | nvd.nist.gov | 2026-08-07 | claude-code | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.