LWN.net Logo

rails: input validation error

Package(s):rails CVE #(s):CVE-2012-5664
Created:January 7, 2013 Updated:January 9, 2013
Description: From the Debian advisory:

joernchen of Phenoelit discovered that rails, an MVC ruby based framework geared for web application development, is not properly treating user-supplied input to "find_by_*" methods. Depending on how the ruby on rails application is using these methods, this allows an attacker to perform SQL injection attacks, e.g., to bypass authentication if Authlogic is used and the session secret token is known.

See this advisory for more information, patches, and workarounds.

Alerts:
Debian DSA-2597-1 2013-01-04
openSUSE openSUSE-SU-2013:0278-1 2013-02-12
openSUSE openSUSE-SU-2013:0280-1 2013-02-12
SUSE SUSE-SU-2013:0486-1 2013-03-19
SUSE SUSE-SU-2013:0508-1 2013-03-20
SUSE SUSE-SU-2013:0606-1 2013-04-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds