HIGH
GHSA-xf96-32q2-9rw2
Rails ActiveRecord gem vulnerable to SQL injection
Quick fix
GHSA-xf96-32q2-9rw2 — activerecord: upgrade to the fixed version with the command below.
bundle update activerecordDetails
Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) `:limit` and (2) `:offset` parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2008-4094[ADVISORY]
- https://github.com/rails/rails/commit/ef0ea782b1f5cf7b08e74ea3002a16c708f66645[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45109[WEB]
- https://github.com/rails/rails[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord/CVE-2008-4094.yml[WEB]
- https://web.archive.org/web/20080620000955/http://blog.innerewut.de/2008/6/16/why-you-should-upgrade-to-rails-2-1[WEB]
- https://web.archive.org/web/20080620201733/http://blog.innerewut.de/files/rails/activerecord-1.15.3.patch[WEB]
- https://web.archive.org/web/20080620201744/http://blog.innerewut.de/files/rails/activerecord-2.0.2.patch[WEB]
- https://web.archive.org/web/20081104151751/http://gist.github.com/8946[WEB]
- https://web.archive.org/web/20081113122736/http://secunia.com/advisories/31875[WEB]
- https://web.archive.org/web/20081207211431/http://secunia.com/advisories/31909[WEB]
- https://web.archive.org/web/20081207211436/http://secunia.com/advisories/31910[WEB]
- https://web.archive.org/web/20091101000000*/http://www.vupen.com/english/advisories/2008/2562[WEB]
- https://web.archive.org/web/20120120194518/http://www.securityfocus.com/bid/31176[WEB]
- https://web.archive.org/web/20201207112829/http://www.securitytracker.com/id?1020871[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html[WEB]
- http://rails.lighthouseapp.com/projects/8994/tickets/288[WEB]
- http://rails.lighthouseapp.com/projects/8994/tickets/964[WEB]
- http://www.openwall.com/lists/oss-security/2008/09/13/2[WEB]
- http://www.openwall.com/lists/oss-security/2008/09/16/1[WEB]
- http://www.rorsecurity.info/2008/09/08/sql-injection-issue-in-limit-and-offset-parameter[WEB]