Sha256: f194699c2402d27217c154a7002cc47c8e92e575f4dc3eb77c357172bca02115

Contents?: true

Size: 531 Bytes

Versions: 1

Compression:

Stored size: 531 Bytes

Contents

---
gem: activerecord
framework: rails
cve: 2014-0080
osvdb: 103438
url: https://nvd.nist.gov/vuln/detail/CVE-2014-0080
title: Data Injection Vulnerability in Active Record
date: 2014-02-18

description: |
  Ruby on Rails contains a flaw in connection_adapters/postgresql/cast.rb
  in Active Record. This issue may allow a remote attacker to inject data
  into PostgreSQL array columns via a specially crafted string.

cvss_v2: 

unaffected_versions:
  - "< 3.2.0"
  - ~> 3.2.0

patched_versions:
  - ~> 4.0.3
  - ">= 4.1.0.beta2"

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/activerecord/CVE-2014-0080.yml