Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-3221

Опубликовано: 07 фев. 2013
Источник: redhat
CVSS2: 5

Описание

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

Отчет

Not a security issue. This issue is due to the handling of data types when passing data between rubygem-activerecord and MySQL. Applications that use rubygem-activerecord and MySQL may be affected if written in a way that exposes the issue, however any flaw would be specific to that application. For further information, please refer to https://bugzilla.redhat.com/show_bug.cgi?id=954365#c5

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1ruby193-rubygem-activerecordNot affected
OpenShift Enterprise 1rubygem-activerecordNot affected
Red Hat CloudForms Tools 1rubygem-activerecordNot affected
Red Hat Subscription Asset Managerrubygem-activerecordNot affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=954365rubygem-activerecord: Data-type injection attacks due absent database column data type (input vs stored value) check

5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

nvd
почти 13 лет назад

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

debian
почти 13 лет назад

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and ...

github
больше 3 лет назад

Active Record component in Ruby on Rails has a data-type injection vulnerability

5 Medium

CVSS2