CVE-2013-3221
published 2013-04-22CVE-2013-3221: The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during…
PriorityP429medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.95%
77.9th percentile
The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activerecord_project | activerecord | >= 0 < 4.2.0 | 4.2.0 |
| debian | rails | < rails 2.3.14.1 (bookworm) | rails 2.3.14.1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4LOW
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Active Record component in Ruby on Rails has a data-type injection vulnerability
osv·2022-05-14
CVE-2013-3221 [CRITICAL] Active Record component in Ruby on Rails has a data-type injection vulnerability
Active Record component in Ruby on Rails has a data-type injection vulnerability
The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.
GHSA
Active Record component in Ruby on Rails has a data-type injection vulnerability
ghsa·2022-05-14
CVE-2013-3221 [CRITICAL] CWE-20 Active Record component in Ruby on Rails has a data-type injection vulnerability
Active Record component in Ruby on Rails has a data-type injection vulnerability
The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.
OSV
CVE-2013-3221: The Active Record component in Ruby on Rails 2
osv·2013-04-22·CVSS 6.4
CVE-2013-3221 [MEDIUM] CVE-2013-3221: The Active Record component in Ruby on Rails 2
The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.
Red Hat
rubygem-activerecord: Data-type injection attacks due absent database column data type (input vs stored value) check
vendor_redhat·2013-02-07·CVSS 6.4
CVE-2013-3221 [MEDIUM] rubygem-activerecord: Data-type injection attacks due absent database column data type (input vs stored value) check
rubygem-activerecord: Data-type injection attacks due absent database column data type (input vs stored value) check
The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.
Statement: Not a security issue. This issue is due to the handling of data types when passing data between rubygem-activerecord and MySQL. Applications that use rubygem-activerecord and MySQL may be affected if written in a way th
Debian
CVE-2013-3221: rails - The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does...
vendor_debian·2013·CVSS 6.4
CVE-2013-3221 [MEDIUM] CVE-2013-3221: rails - The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does...
The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: resolved (fixed in 2.3.14.1)
sid: resolved (fixed in 2.3.14.1)
trixie: resolved (fixed in 2.3.14.1)
No detection rules found.
No public exploits indexed.
http://openwall.com/lists/oss-security/2013/02/06/7http://openwall.com/lists/oss-security/2013/04/24/7http://pl.reddit.com/r/netsec/comments/17yajp/mysql_madness_and_rails/http://www.phenoelit.org/blog/archives/2013/02/index.htmlhttps://gist.github.com/dakull/5442275https://groups.google.com/group/rubyonrails-security/msg/1f3bc0b88a60c1ce?dmode=source&output=gplainhttp://openwall.com/lists/oss-security/2013/02/06/7http://openwall.com/lists/oss-security/2013/04/24/7http://pl.reddit.com/r/netsec/comments/17yajp/mysql_madness_and_rails/http://www.phenoelit.org/blog/archives/2013/02/index.htmlhttps://gist.github.com/dakull/5442275https://groups.google.com/group/rubyonrails-security/msg/1f3bc0b88a60c1ce?dmode=source&output=gplain
2013-04-22
Published