Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-3221

Опубликовано: 07 фев. 2013
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

Отчет

Not a security issue. This issue is due to the handling of data types when passing data between rubygem-activerecord and MySQL. Applications that use rubygem-activerecord and MySQL may be affected if written in a way that exposes the issue, however any flaw would be specific to that application. For further information, please refer to https://bugzilla.redhat.com/show_bug.cgi?id=954365#c5

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1ruby193-rubygem-activerecordNot affected
OpenShift Enterprise 1rubygem-activerecordNot affected
Red Hat Subscription Asset Managerrubygem-activerecordNot affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=954365rubygem-activerecord: Data-type injection attacks due absent database column data type (input vs stored value) check

EPSS

Процентиль: 78%
0.01962
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

nvd
больше 13 лет назад

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

debian
больше 13 лет назад

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and ...

github
около 4 лет назад

Active Record component in Ruby on Rails has a data-type injection vulnerability

EPSS

Процентиль: 78%
0.01962
Низкий

5 Medium

CVSS2