VDB
Sign up
MEDIUM

GHSA-hqf9-rc9j-5fmj

Array data injection vulnerability in activerecord

Quick fix

GHSA-hqf9-rc9j-5fmj — activerecord: upgrade to the fixed version with the command below.

bundle update activerecord

Details

SQL injection vulnerability in `activerecord/lib/active_record/connection_adapters/postgresql/cast.rb` in Active Record in Ruby on Rails 4.0.x before 4.0.3, and 4.1.0.beta1, when PostgreSQL is used, allows remote attackers to execute "add data" SQL commands via vectors involving `\` (backslash) characters that are not properly handled in operations on array columns.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activerecord
Introduced in: 4.0.0Fixed in: 4.0.3
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 4.1.0.beta1Fixed in: 4.1.0.beta2
Fixbundle update activerecord

References