VDB
Sign up
HIGH

GHSA-h6w6-xmqv-7q78

activerecord vulnerable to SQL Injection

Quick fix

GHSA-h6w6-xmqv-7q78 — activerecord: upgrade to the fixed version with the command below.

bundle update activerecord

Details

Multiple SQL injection vulnerabilities in the `quote_table_name` method in the ActiveRecord adapters in `activerecord/lib/active_record/connection_adapters/` in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allow remote attackers to execute arbitrary SQL commands via a crafted column name.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activerecord
Introduced in: 2.0.0Fixed in: 2.3.13
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 3.0.0.betaFixed in: 3.0.10
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 3.1.0.beta1Fixed in: 3.1.0.rc5
Fixbundle update activerecord

References