VDB
Sign up
HIGH

GHSA-gh2w-j7cx-2664

Active Record contains SQL Injection

Quick fix

GHSA-gh2w-j7cx-2664 — activerecord: upgrade to the fixed version with the command below.

bundle update activerecord

Details

SQL injection vulnerability in the Active Record component in Ruby on Rails before 2.3.15, 3.0.x before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activerecord
Introduced in: 3.0.0.betaFixed in: 3.0.18
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 3.1.0Fixed in: 3.1.9
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 3.2.0Fixed in: 3.2.10
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 0Fixed in: 2.3.15
Fixbundle update activerecord

References