CVE-2013-0277: rubygem-activerecord: Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0

Severity: Critical

CVSS Score: 10

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.