HIGH
GHSA-5qw5-wf2q-f538
ActiveRecord-JDBC-Adapter (AR-JDBC) lib/arjdbc/jdbc/adapter.rb sql.gsub() Function SQL Injection
Quick fix
GHSA-5qw5-wf2q-f538 — activerecord-jdbc-adapter: upgrade to the fixed version with the command below.
bundle update activerecord-jdbc-adapterDetails
ActiveRecord-JDBC-Adapter (AR-JDBC) contains a flaw that may allow carrying out an SQL injection attack. The issue is due to the sql.gsub() function in lib/arjdbc/jdbc/adapter.rb not properly sanitizing user-supplied input before using it in SQL queries. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
Are you affected?
Enter the version of the package you're using.
Affected packages
RubyGems/activerecord-jdbc-adapter
Introduced in:
0Fixed in: 1.2.8Fix
bundle update activerecord-jdbc-adapterReferences
- https://github.com/jruby/activerecord-jdbc-adapter/issues/322[WEB]
- https://github.com/jruby/activerecord-jdbc-adapter[PACKAGE]
- https://github.com/jruby/activerecord-jdbc-adapter/blob/master/lib/arjdbc/jdbc/adapter.rb[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord-jdbc-adapter/GHSA-5qw5-wf2q-f538.yml[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord-jdbc-adapter/OSVDB-114854.yml[WEB]