CVE-2014-3482
published 2014-07-07CVE-2014-3482: SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on…
PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.28%
90.0th percentile
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting.
Affected
81 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activerecord_project | activerecord | >= 2.0.0 < 3.2.19 | 3.2.19 |
| debian | rails | < rails 2:4.1.4-1 (bookworm) | rails 2:4.1.4-1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-activerecord: SQL injection vulnerability in 'bitstring' quoting
vendor_redhat·2014-07-02·CVSS 7.5
CVE-2014-3482 [HIGH] CWE-89 rubygem-activerecord: SQL injection vulnerability in 'bitstring' quoting
rubygem-activerecord: SQL injection vulnerability in 'bitstring' quoting
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting.
It was discovered that Active Record did not properly quote values of the bitstring type attributes when using the PostgreSQL database adapter. A remote attacker could possibly use this flaw to conduct an SQL injection attack against applications using Active Record.
Statement: This issue does not affect CloudForms 5 as it does not use the "bitstring" data type anywhere in the product.
Package: ruby193-rubygem-activerecord (Clou
Debian
CVE-2014-3482: rails - SQL injection vulnerability in activerecord/lib/active_record/connection_adapter...
vendor_debian·2014·CVSS 7.5
CVE-2014-3482 [HIGH] CVE-2014-3482: rails - SQL injection vulnerability in activerecord/lib/active_record/connection_adapter...
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting.
Scope: local
bookworm: resolved (fixed in 2:4.1.4-1)
bullseye: resolved (fixed in 2:4.1.4-1)
forky: resolved (fixed in 2:4.1.4-1)
sid: resolved (fixed in 2:4.1.4-1)
trixie: resolved (fixed in 2:4.1.4-1)
GHSA
SQL Injection in Active Record
ghsa·2017-10-24
CVE-2014-3482 [HIGH] CWE-89 SQL Injection in Active Record
SQL Injection in Active Record
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting.
OSV
SQL Injection in Active Record
osv·2017-10-24
CVE-2014-3482 [HIGH] SQL Injection in Active Record
SQL Injection in Active Record
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting.
OSV
CVE-2014-3482: SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter
osv·2014-07-07·CVSS 7.5
CVE-2014-3482 [HIGH] CVE-2014-3482: SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3482 rubygem-activerecord: SQL injection vulnerability in 'bitstring' quoting [epel-5]
bugzilla·2014-07-03·CVSS 7.5
CVE-2014-3482 [HIGH] CVE-2014-3482 rubygem-activerecord: SQL injection vulnerability in 'bitstring' quoting [epel-5]
CVE-2014-3482 rubygem-activerecord: SQL injection vulnerability in 'bitstring' quoting [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 trac
Bugzilla
CVE-2014-3482 rubygem-activerecord: SQL injection vulnerability in 'bitstring' quoting [fedora-19]
bugzilla·2014-07-03·CVSS 7.5
CVE-2014-3482 [HIGH] CVE-2014-3482 rubygem-activerecord: SQL injection vulnerability in 'bitstring' quoting [fedora-19]
CVE-2014-3482 rubygem-activerecord: SQL injection vulnerability in 'bitstring' quoting [fedora-19]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-19 tra
Bugzilla
CVE-2014-3482 rubygem-activerecord: SQL injection vulnerability in 'bitstring' quoting
bugzilla·2014-06-30·CVSS 7.5
CVE-2014-3482 [HIGH] CVE-2014-3482 rubygem-activerecord: SQL injection vulnerability in 'bitstring' quoting
CVE-2014-3482 rubygem-activerecord: SQL injection vulnerability in 'bitstring' quoting
An SQL injection flaw was found in the PostgreSQL adapter for Active Record. An attacker could possibly perform SQL injection attacks if a Ruby on Rails application performed queries against the bitstring type.
This issue affects versions 2.0.0-3.2.18 and newer. It is reported that versions 4.0 and newer are not affected.
Acknowledgements:
Red Hat would like to thank the Ruby on Rails project for reporting this issue. Upstream acknowledges Sean Griffin of thoughtbot as the original reporter.
Discussion:
Created attachment 913247
patch from upstream
---
This is now public:
https://groups.google.com/forum/#!topic/rubyonrails-security/wDxePLJGZdI
---
Statement:
This issue does not affect CloudFor
http://openwall.com/lists/oss-security/2014/07/02/5http://rhn.redhat.com/errata/RHSA-2014-0876.htmlhttp://secunia.com/advisories/59973http://secunia.com/advisories/60214http://secunia.com/advisories/60763http://www.debian.org/security/2014/dsa-2982http://www.securityfocus.com/bid/68343https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wDxePLJGZdI/WP7EasCJTA4Jhttp://openwall.com/lists/oss-security/2014/07/02/5http://rhn.redhat.com/errata/RHSA-2014-0876.htmlhttp://secunia.com/advisories/59973http://secunia.com/advisories/60214http://secunia.com/advisories/60763http://www.debian.org/security/2014/dsa-2982http://www.securityfocus.com/bid/68343https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wDxePLJGZdI/WP7EasCJTA4J
2014-07-07
Published