|
|
| |
|
| |
rubygem-activerecord: SQL injection
| Package(s): | rubygem-activerecord |
CVE #(s): | CVE-2012-2695
|
| Created: | July 2, 2012 |
Updated: | August 21, 2012 |
| Description: |
From the CVE entry:
The Active Record component in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that leverage improper handling of nested hashes, a related issue to CVE-2012-2661. |
| Alerts: |
|
( Log in to post comments)
|
|
|