Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hqf9-rc9j-5fmj

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Array data injection vulnerability in activerecord

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3, and 4.1.0.beta1, when PostgreSQL is used, allows remote attackers to execute "add data" SQL commands via vectors involving \ (backslash) characters that are not properly handled in operations on array columns.

Пакеты

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.3

4.0.3

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

= 4.1.0.beta1

4.1.0.beta2

EPSS

Процентиль: 48%
0.00248
Низкий

Дефекты

CWE-89

Связанные уязвимости

ubuntu
почти 12 лет назад

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3, and 4.1.0.beta1, when PostgreSQL is used, allows remote attackers to execute "add data" SQL commands via vectors involving \ (backslash) characters that are not properly handled in operations on array columns.

redhat
почти 12 лет назад

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3, and 4.1.0.beta1, when PostgreSQL is used, allows remote attackers to execute "add data" SQL commands via vectors involving \ (backslash) characters that are not properly handled in operations on array columns.

nvd
почти 12 лет назад

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3, and 4.1.0.beta1, when PostgreSQL is used, allows remote attackers to execute "add data" SQL commands via vectors involving \ (backslash) characters that are not properly handled in operations on array columns.

debian
почти 12 лет назад

SQL injection vulnerability in activerecord/lib/active_record/connecti ...

EPSS

Процентиль: 48%
0.00248
Низкий

Дефекты

CWE-89