CVE-2013-6417
published 2013-12-07CVE-2013-6417: actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling…
PriorityP434medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.37%
81.9th percentile
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request that leverages (1) third-party Rack middleware or (2) custom Rack middleware. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-0155.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 3.0.0 < 3.2.16 | 3.2.16 |
| actionpack_project | actionpack | >= 4.0.0 < 4.0.2 | 4.0.2 |
| debian | rails | — | — |
| rubyonrails | rails | <= 4.0.1 | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
ghsa6.4MEDIUM
osv6.4MEDIUM
vendor_debian6.4LOW
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
actionpack allows bypass of database-query restrictions
ghsa·2017-10-24·CVSS 6.4
CVE-2013-6417 [MEDIUM] CWE-284 actionpack allows bypass of database-query restrictions
actionpack allows bypass of database-query restrictions
`actionpack/lib/action_dispatch/http/request.rb` in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request that leverages (1) third-party Rack middleware or (2) custom Rack middleware. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-0155.
OSV
actionpack allows bypass of database-query restrictions
osv·2017-10-24·CVSS 6.4
CVE-2013-6417 [MEDIUM] actionpack allows bypass of database-query restrictions
actionpack allows bypass of database-query restrictions
`actionpack/lib/action_dispatch/http/request.rb` in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request that leverages (1) third-party Rack middleware or (2) custom Rack middleware. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-0155.
OSV
CVE-2013-6417: actionpack/lib/action_dispatch/http/request
osv·2013-12-07·CVSS 6.4
CVE-2013-6417 [MEDIUM] CVE-2013-6417: actionpack/lib/action_dispatch/http/request
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request that leverages (1) third-party Rack middleware or (2) custom Rack middleware. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-0155.
Red Hat
rubygem-actionpack: unsafe query generation risk (incomplete fix for CVE-2013- 0155)
vendor_redhat·2013-12-03·CVSS 6.4
CVE-2013-6417 [MEDIUM] CWE-89 rubygem-actionpack: unsafe query generation risk (incomplete fix for CVE-2013- 0155)
rubygem-actionpack: unsafe query generation risk (incomplete fix for CVE-2013- 0155)
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request that leverages (1) third-party Rack middleware or (2) custom Rack middleware. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-0155.
Package: ruby193-rubygem-actionpack (OpenShift Enterprise 1) - Will not fix
Package: ruby193-rubygem-actionpack (Red Hat OpenStack Platform 4) - Affected
Package: ruby193-r
Debian
CVE-2013-6417: rails - actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 an...
vendor_debian·2013·CVSS 6.4
CVE-2013-6417 [MEDIUM] CVE-2013-6417: rails - actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 an...
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request that leverages (1) third-party Rack middleware or (2) custom Rack middleware. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-0155.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00081.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00082.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1794.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0008.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0469.htmlhttp://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/http://www.debian.org/security/2014/dsa-2888https://groups.google.com/forum/message/raw?msg=ruby-security-ann/niK4drpSHT4/g8JW8ZsayRkJhttps://puppet.com/security/cve/cve-2013-6417http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00081.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00082.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1794.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0008.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0469.htmlhttp://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/http://www.debian.org/security/2014/dsa-2888https://groups.google.com/forum/message/raw?msg=ruby-security-ann/niK4drpSHT4/g8JW8ZsayRkJhttps://puppet.com/security/cve/cve-2013-6417
2013-12-07
Published