CVE-2012-2661SQL Injection in Project Activerecord

CWE-89SQL Injection13 documents7 sources
Severity
5.0MEDIUMNVD
GHSA7.5OSV7.5
EPSS
0.7%
top 27.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 22
Latest updateOct 24

Description

The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that leverage unintended recursion, a related issue to CVE-2012-2695.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

RubyGemsactiverecord_project/activerecord3.0.03.0.13+2
NVDrubyonrails/rails25 versions+24

🔴Vulnerability Details

4
GHSA
Active Record vulnerable to SQL Injection via nested query parameters2017-10-24
OSV
Active Record vulnerable to SQL Injection via nested query parameters2017-10-24
GHSA
activerecord vulnerable to SQL Injection2017-10-24
CVEList
CVE-2012-2661: The Active Record component in Ruby on Rails 32012-06-22

📋Vendor Advisories

3
Red Hat
rubygem-activerecord: SQL injection when processing nested query paramaters (a different flaw than CVE-2012-2661)2012-06-12
Red Hat
rubygem-activerecord: SQL injection when processing nested query paramaters2012-05-31
Debian
CVE-2012-2661: rails - The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3...2012

💬Community

5
Bugzilla
CVE-2012-2695 rubygem-activerecord: SQL injection when processing nested query paramaters (a different flaw than CVE-2012-2661)2012-06-13
Bugzilla
CVE-2012-2695 rubygem-activerecord: SQL injection when processing nested query paramaters (a different flaw than CVE-2012-2661) [fedora-all]2012-06-13
Bugzilla
CVE-2012-2695 rubygem-activerecord: SQL injection when processing nested query paramaters (a different flaw than CVE-2012-2661) [epel-5]2012-06-13
Bugzilla
CVE-2012-2661 rubygem-activerecord: SQL injection when processing nested query paramaters2012-06-01
Bugzilla
CVE-2012-2661 rubygem-activerecord: SQL injection when processing nested query paramaters [fedora-all]2012-06-01
CVE-2012-2661 — SQL Injection in Project Activerecord | cvebase