Описание
SQL injection in blazer
Blazer before 2.6.0 allows SQL Injection. In certain circumstances, an attacker could get a user to run a query they would not have normally run.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-29498
- https://github.com/ankane/blazer/issues/391
- https://github.com/ankane/blazer/issues/392
- https://github.com/ankane/blazer/commit/f49fbfed7b9e406a69eb78c463c3aa5d35006d8d"
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/blazer/CVE-2022-29498.yml
Пакеты
Наименование
blazer
rubygems
Затронутые версииВерсия исправления
< 2.6.0
2.6.0
Связанные уязвимости
CVSS3: 7.5
nvd
почти 4 года назад
Blazer before 2.6.0 allows SQL Injection. In certain circumstances, an attacker could get a user to run a query they would not have normally run.