Sha256: 6636bfe53b8778e28bf6bb1350980a6a32de0e7a0c8cb680efde4dd1deccc14a

Contents?: true

Size: 702 Bytes

Versions: 14

Compression:

Stored size: 702 Bytes

Contents

--- 
gem: activerecord
framework: rails
cve: 2012-2661
osvdb: 82403
url: http://www.osvdb.org/show/osvdb/82403
title: Ruby on Rails where Method ActiveRecord Class SQL Injection
date: 2012-05-31

description: |
  Ruby on Rails (RoR) contains a flaw that may allow an attacker to carry out
  an SQL injection attack. The issue is due to the ActiveRecord class not
  properly sanitizing user-supplied input to the 'where' method. This may
  allow an attacker to inject or manipulate SQL queries in an application
  built on RoR, allowing for the manipulation or disclosure of arbitrary data.

cvss_v2: 5.0

unaffected_versions:
  - ~> 2.3.14

patched_versions: 
  - ~> 3.0.13
  - ~> 3.1.5
  - ">= 3.2.4"

Version data entries

14 entries across 14 versions & 3 rubygems

Version Path
bundler-budit-0.6.2 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
bundler-audit-0.6.1 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
bundler-audit-0.6.0 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
bundler-audit-0.5.0 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
bundler-audit-0.4.0 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
bundler-audit-0.3.1 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
mrjoy-bundler-audit-0.3.3 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
mrjoy-bundler-audit-0.3.2 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
mrjoy-bundler-audit-0.3.1 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
bundler-audit-0.3.0 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
mrjoy-bundler-audit-0.2.1 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
bundler-audit-0.2.0 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml
mrjoy-bundler-audit-0.1.4 data/ruby-advisory-db/gems/activerecord/OSVDB-82403.yml