CVE-2012-6497
published 2013-01-04CVE-2012-6497: The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote…
PriorityP427medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.74%
84.6th percentile
The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in secret_token.rb in an open-source product.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | < rails 2.3.14.1 (bookworm) | rails 2.3.14.1 (bookworm) |
| rubyonrails | rails | < 3.2.10 | 3.2.10 |
| rubyonrails | rails | >= 0 < 2.3.14.1 | 2.3.14.1 |
| rubyonrails | rails | >= 0 < 2.3.14.1 | 2.3.14.1 |
| rubyonrails | rails | >= 0 < 2.3.14.1 | 2.3.14.1 |
| rubyonrails | rails | >= 0 < 2.3.14.1 | 2.3.14.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Authlogic Information Exposure vulnerability
ghsa·2022-05-14·CVSS 7.5
CVE-2012-6497 [HIGH] CWE-200 Authlogic Information Exposure vulnerability
Authlogic Information Exposure vulnerability
The Authlogic gem for Ruby on Rails prior to version 3.3.0 makes potentially unsafe `find_by_id` method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in `secret_token.rb` in an open-source product.
OSV
Authlogic Information Exposure vulnerability
osv·2022-05-14·CVSS 7.5
CVE-2012-6497 [HIGH] Authlogic Information Exposure vulnerability
Authlogic Information Exposure vulnerability
The Authlogic gem for Ruby on Rails prior to version 3.3.0 makes potentially unsafe `find_by_id` method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in `secret_token.rb` in an open-source product.
OSV
CVE-2012-6497: The Authlogic gem for Ruby on Rails, when used with certain versions before 3
osv·2013-01-04·CVSS 7.5
CVE-2012-6497 [HIGH] CVE-2012-6497: The Authlogic gem for Ruby on Rails, when used with certain versions before 3
The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in secret_token.rb in an open-source product.
Debian
CVE-2012-6497: rails - The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2....
vendor_debian·2012·CVSS 7.5
CVE-2012-6497 [HIGH] CVE-2012-6497: rails - The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2....
The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in secret_token.rb in an open-source product.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: resolved (fixed in 2.3.14.1)
sid: resolved (fixed in 2.3.14.1)
trixie: resolved (fixed in 2.3.14.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls
bugzilla·2013-01-04·CVSS 7.5
CVE-2012-6497 [HIGH] CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls
CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-6497 to
the following vulnerability:
Name: CVE-2012-6497
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6497
Assigned: 20130103
Reference: http://openwall.com/lists/oss-security/2013/01/03/12
Reference: http://blog.phusion.nl/2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-facts/
Reference: http://phenoelit.org/blog/archives/2012/12/21/let_me_github_that_for_you/index.html
The Authlogic gem for Ruby on Rails, when used with certain versions
before 3.2.10, makes potentially unsafe find_by_id method calls, which
might allow remote attackers to conduct CVE-2012-6496 SQL injection
attacks via a crafted paramete
Bugzilla
CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls [fedora-all]
bugzilla·2013-01-04·CVSS 5.0
CVE-2012-6497 [MEDIUM] CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls [fedora-all]
CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this
Bugzilla
CVE-2012-6496 rubygem-activerecord: find_by_* SQL Injection
bugzilla·2012-12-22·CVSS 7.5
CVE-2012-6496 [HIGH] CVE-2012-6496 rubygem-activerecord: find_by_* SQL Injection
CVE-2012-6496 rubygem-activerecord: find_by_* SQL Injection
This issue was found on the Phenoelit Blog:
An authlogic cookie usually uses a database stored token to identify the user. The relevant parts of the session cookie are:
user_credentials_id - a numeric value which is used with "User.find_by_id()"
user_credentials - a radom string which will be compared with the database field "persistence_token" in the Users table
Due to the way the RoR "find_by_*" methods are defined the following SQL injection a-like issue arises:
> User.find_by_id({:select =>"* from users limit 1 --"})
User Load (0.5ms) SELECT * from users limit 1 -- FROM "users" WHERE "users"."id" IS NULL LIMIT 1
=> # "41414141",
"user_credentials"=>"Phenoelit",
"user_credentials_id"=>{
:select=> " *,\"Phenoelit\" as persi
http://blog.phusion.nl/2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-facts/http://openwall.com/lists/oss-security/2013/01/03/12http://phenoelit.org/blog/archives/2012/12/21/let_me_github_that_for_you/index.htmlhttp://www.securityfocus.com/bid/57084http://blog.phusion.nl/2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-facts/http://openwall.com/lists/oss-security/2013/01/03/12http://phenoelit.org/blog/archives/2012/12/21/let_me_github_that_for_you/index.htmlhttp://www.securityfocus.com/bid/57084
2013-01-04
Published