Sha256: 784b8d6a8c90fa0473bc6567234a7beb7c7d4dac68f799e0e67b0d8aeac0f7b4

Contents?: true

Size: 632 Bytes

Versions: 1

Compression:

Stored size: 632 Bytes

Contents

--- 
gem: activerecord
cve: 2012-2660
url: http://www.osvdb.org/show/osvdb/82610
title:
  Ruby on Rails ActiveRecord Class Rack Query Parameter Parsing SQL Query
  Arbitrary IS NULL Clause Injection

description: |
  Ruby on Rails contains a flaw related to the way ActiveRecord handles
  parameters in conjunction with the way Rack parses query parameters.
  This issue may allow an attacker to inject arbitrary 'IS NULL' clauses in
  to application SQL queries. This may also allow an attacker to have the
  SQL query check for NULL in arbitrary places.

cvss_v2: 7.5

patched_versions: 
  - ~> 3.0.13
  - ~> 3.1.5
  - ">= 3.2.4"

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.1.2 data/ruby-advisory-db/gems/activerecord/2012-2660.yml