Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-6496

Опубликовано: 21 дек. 2012
Источник: redhat
CVSS2: 6.4
EPSS Низкий

Описание

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1ruby-rubygem-activerecordAffected
Red Hat CloudForms Tools 1rubygem-activerecordWill not fix
CloudForms for RHEL 6rubygem-actionpackFixedRHSA-2013:015510.01.2013
CloudForms for RHEL 6rubygem-activerecordFixedRHSA-2013:015510.01.2013
CloudForms for RHEL 6rubygem-activesupportFixedRHSA-2013:015510.01.2013
Red Hat Subscription Asset Manager 1.1rubygem-actionpackFixedRHSA-2013:015410.01.2013
Red Hat Subscription Asset Manager 1.1rubygem-activerecordFixedRHSA-2013:015410.01.2013
Red Hat Subscription Asset Manager 1.1rubygem-activesupportFixedRHSA-2013:015410.01.2013
RHEL 6 Version of OpenShift EnterprisejenkinsFixedRHSA-2013:022031.01.2013
RHEL 6 Version of OpenShift EnterprisemongodbFixedRHSA-2013:022031.01.2013

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=889649rubygem-activerecord: find_by_* SQL Injection

EPSS

Процентиль: 84%
0.02213
Низкий

6.4 Medium

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.

nvd
около 13 лет назад

SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.

debian
около 13 лет назад

SQL injection vulnerability in the Active Record component in Ruby on ...

github
больше 8 лет назад

Active Record contains SQL Injection

EPSS

Процентиль: 84%
0.02213
Низкий

6.4 Medium

CVSS2