CVE-2012-6496
published 2013-01-04CVE-2012-6496: SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers…
PriorityP348high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.46%
90.4th percentile
SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activerecord_project | activerecord | >= 0 < 2.3.15 | 2.3.15 |
| activerecord_project | activerecord | >= 3.0.0.beta < 3.0.18 | 3.0.18 |
| activerecord_project | activerecord | >= 3.1.0 < 3.1.9 | 3.1.9 |
| activerecord_project | activerecord | >= 3.2.0 < 3.2.10 | 3.2.10 |
| debian | rails | < rails 2.3.14.1 (bookworm) | rails 2.3.14.1 (bookworm) |
| rubyonrails | rails | < 3.2.10 | 3.2.10 |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Authlogic Information Exposure vulnerability
ghsa·2022-05-14·CVSS 7.5
CVE-2012-6497 [HIGH] CWE-200 Authlogic Information Exposure vulnerability
Authlogic Information Exposure vulnerability
The Authlogic gem for Ruby on Rails prior to version 3.3.0 makes potentially unsafe `find_by_id` method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in `secret_token.rb` in an open-source product.
OSV
Authlogic Information Exposure vulnerability
osv·2022-05-14·CVSS 7.5
CVE-2012-6497 [HIGH] Authlogic Information Exposure vulnerability
Authlogic Information Exposure vulnerability
The Authlogic gem for Ruby on Rails prior to version 3.3.0 makes potentially unsafe `find_by_id` method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in `secret_token.rb` in an open-source product.
OSV
Active Record contains SQL Injection
osv·2017-10-24
CVE-2012-6496 [HIGH] Active Record contains SQL Injection
Active Record contains SQL Injection
SQL injection vulnerability in the Active Record component in Ruby on Rails before 2.3.15, 3.0.x before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.
GHSA
Active Record contains SQL Injection
ghsa·2017-10-24
CVE-2012-6496 [HIGH] CWE-89 Active Record contains SQL Injection
Active Record contains SQL Injection
SQL injection vulnerability in the Active Record component in Ruby on Rails before 2.3.15, 3.0.x before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.
OSV
CVE-2012-6497: The Authlogic gem for Ruby on Rails, when used with certain versions before 3
osv·2013-01-04·CVSS 7.5
CVE-2012-6497 [HIGH] CVE-2012-6497: The Authlogic gem for Ruby on Rails, when used with certain versions before 3
The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in secret_token.rb in an open-source product.
OSV
CVE-2012-6496: SQL injection vulnerability in the Active Record component in Ruby on Rails before 3
osv·2013-01-04·CVSS 7.5
CVE-2012-6496 [HIGH] CVE-2012-6496: SQL injection vulnerability in the Active Record component in Ruby on Rails before 3
SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.
Red Hat
rubygem-activerecord: find_by_* SQL Injection
vendor_redhat·2012-12-21·CVSS 7.5
CVE-2012-6496 [HIGH] CWE-89 rubygem-activerecord: find_by_* SQL Injection
rubygem-activerecord: find_by_* SQL Injection
SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.
Package: ruby-rubygem-activerecord (OpenShift Enterprise 1) - Affected
Debian
CVE-2012-6497: rails - The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2....
vendor_debian·2012·CVSS 7.5
CVE-2012-6497 [HIGH] CVE-2012-6497: rails - The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2....
The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in secret_token.rb in an open-source product.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: resolved (fixed in 2.3.14.1)
sid: resolved (fixed in 2.3.14.1)
trixie: resolved (fixed in 2.3.14.1)
Debian
CVE-2012-6496: rails - SQL injection vulnerability in the Active Record component in Ruby on Rails befo...
vendor_debian·2012·CVSS 7.5
CVE-2012-6496 [HIGH] CVE-2012-6496: rails - SQL injection vulnerability in the Active Record component in Ruby on Rails befo...
SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: resolved (fixed in 2.3.14.1)
sid: resolved (fixed in 2.3.14.1)
trixie: resolved (fixed in 2.3.14.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls
bugzilla·2013-01-04·CVSS 7.5
CVE-2012-6497 [HIGH] CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls
CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-6497 to
the following vulnerability:
Name: CVE-2012-6497
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6497
Assigned: 20130103
Reference: http://openwall.com/lists/oss-security/2013/01/03/12
Reference: http://blog.phusion.nl/2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-facts/
Reference: http://phenoelit.org/blog/archives/2012/12/21/let_me_github_that_for_you/index.html
The Authlogic gem for Ruby on Rails, when used with certain versions
before 3.2.10, makes potentially unsafe find_by_id method calls, which
might allow remote attackers to conduct CVE-2012-6496 SQL injection
attacks via a crafted paramete
Bugzilla
CVE-2012-6496 rubygem-activerecord: find_by_* SQL Injection [fedora-all]
bugzilla·2013-01-03·CVSS 7.5
CVE-2012-6496 [HIGH] CVE-2012-6496 rubygem-activerecord: find_by_* SQL Injection [fedora-all]
CVE-2012-6496 rubygem-activerecord: find_by_* SQL Injection [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2012-6496 rubygem-activerecord: find_by_* SQL Injection [epel-5]
bugzilla·2013-01-03·CVSS 7.5
CVE-2012-6496 [HIGH] CVE-2012-6496 rubygem-activerecord: find_by_* SQL Injection [epel-5]
CVE-2012-6496 rubygem-activerecord: find_by_* SQL Injection [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for rubygem
Bugzilla
CVE-2012-6496 rubygem-activerecord: find_by_* SQL Injection
bugzilla·2012-12-22·CVSS 7.5
CVE-2012-6496 [HIGH] CVE-2012-6496 rubygem-activerecord: find_by_* SQL Injection
CVE-2012-6496 rubygem-activerecord: find_by_* SQL Injection
This issue was found on the Phenoelit Blog:
An authlogic cookie usually uses a database stored token to identify the user. The relevant parts of the session cookie are:
user_credentials_id - a numeric value which is used with "User.find_by_id()"
user_credentials - a radom string which will be compared with the database field "persistence_token" in the Users table
Due to the way the RoR "find_by_*" methods are defined the following SQL injection a-like issue arises:
> User.find_by_id({:select =>"* from users limit 1 --"})
User Load (0.5ms) SELECT * from users limit 1 -- FROM "users" WHERE "users"."id" IS NULL LIMIT 1
=> # "41414141",
"user_credentials"=>"Phenoelit",
"user_credentials_id"=>{
:select=> " *,\"Phenoelit\" as persi
http://blog.phusion.nl/2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-facts/http://rhn.redhat.com/errata/RHSA-2013-0154.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0155.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0220.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0544.htmlhttp://security.gentoo.org/glsa/glsa-201401-22.xmlhttp://www.securityfocus.com/bid/57084https://bugzilla.redhat.com/show_bug.cgi?id=889649https://groups.google.com/group/rubyonrails-security/msg/23daa048baf28b64?dmode=source&output=gplainhttp://blog.phusion.nl/2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-facts/http://rhn.redhat.com/errata/RHSA-2013-0154.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0155.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0220.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0544.htmlhttp://security.gentoo.org/glsa/glsa-201401-22.xmlhttp://www.securityfocus.com/bid/57084https://bugzilla.redhat.com/show_bug.cgi?id=889649https://groups.google.com/group/rubyonrails-security/msg/23daa048baf28b64?dmode=source&output=gplain
2013-01-04
Published