CVE-2014-3483
published 2014-07-07CVE-2014-3483: SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on…
PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.18%
89.8th percentile
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activerecord_project | activerecord | >= 4.0.0 < 4.0.7 | 4.0.7 |
| activerecord_project | activerecord | >= 4.1.0 < 4.1.3 | 4.1.3 |
| debian | rails | < rails 2:4.1.4-1 (bookworm) | rails 2:4.1.4-1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | >= 0 < 2:4.1.4-1 | 2:4.1.4-1 |
| rubyonrails | rails | >= 0 < 2:4.1.4-1 | 2:4.1.4-1 |
| rubyonrails | rails | >= 0 < 2:4.1.4-1 | 2:4.1.4-1 |
| rubyonrails | rails | >= 0 < 2:4.1.4-1 | 2:4.1.4-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Active Record contains SQL Injection via improper range quoting
ghsa·2017-10-24
CVE-2014-3483 [HIGH] CWE-89 Active Record contains SQL Injection via improper range quoting
Active Record contains SQL Injection via improper range quoting
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.
OSV
Active Record contains SQL Injection via improper range quoting
osv·2017-10-24
CVE-2014-3483 [HIGH] Active Record contains SQL Injection via improper range quoting
Active Record contains SQL Injection via improper range quoting
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.
OSV
CVE-2014-3483: SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting
osv·2014-07-07·CVSS 7.5
CVE-2014-3483 [HIGH] CVE-2014-3483: SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.
Red Hat
rubygem-activerecord: SQL injection vulnerability in 'range' quoting
vendor_redhat·2014-07-02·CVSS 7.5
CVE-2014-3483 [HIGH] CWE-89 rubygem-activerecord: SQL injection vulnerability in 'range' quoting
rubygem-activerecord: SQL injection vulnerability in 'range' quoting
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.
It was discovered that Active Record did not properly quote values of the range type attributes when using the PostgreSQL database adapter. A remote attacker could possibly use this flaw to conduct an SQL injection attack against applications using Active Record.
Package: ruby193-rubygem-activerecord (CloudForms Management Engine 5) - Not affected
Package: ruby193-rubygem-activerecord (OpenShift Enterprise 1) - Not affecte
Debian
CVE-2014-3483: rails - SQL injection vulnerability in activerecord/lib/active_record/connection_adapter...
vendor_debian·2014·CVSS 7.5
CVE-2014-3483 [HIGH] CVE-2014-3483: rails - SQL injection vulnerability in activerecord/lib/active_record/connection_adapter...
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.
Scope: local
bookworm: resolved (fixed in 2:4.1.4-1)
bullseye: resolved (fixed in 2:4.1.4-1)
forky: resolved (fixed in 2:4.1.4-1)
sid: resolved (fixed in 2:4.1.4-1)
trixie: resolved (fixed in 2:4.1.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3483 rubygem-activerecord: SQL injection vulnerability in 'range' quoting [fedora-20]
bugzilla·2014-07-03·CVSS 7.5
CVE-2014-3483 [HIGH] CVE-2014-3483 rubygem-activerecord: SQL injection vulnerability in 'range' quoting [fedora-20]
CVE-2014-3483 rubygem-activerecord: SQL injection vulnerability in 'range' quoting [fedora-20]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-20 trackin
Bugzilla
CVE-2014-3483 rubygem-activerecord: SQL injection vulnerability in 'range' quoting
bugzilla·2014-06-30·CVSS 7.5
CVE-2014-3483 [HIGH] CVE-2014-3483 rubygem-activerecord: SQL injection vulnerability in 'range' quoting
CVE-2014-3483 rubygem-activerecord: SQL injection vulnerability in 'range' quoting
An SQL injection flaw was found in the PostgreSQL adapter for Active Record. An attacker could possibly perform SQL injection attacks if a Ruby on Rails application performed queries against the range type.
This issue affects versions 4.0.0 to 4.1.2. It is reported that versions earlier than 4.0 are not affected.
Acknowledgements:
Red Hat would like to thank the Ruby on Rails project for reporting this issue. Upstream acknowledges Sean Griffin of thoughtbot as the original reporter.
Discussion:
Created attachment 913248
4.0 patch from upstream
---
Created attachment 913249
4.1 patch from upstream
---
This is now public:
https://groups.google.com/forum/#!topic/rubyonrails-security/wDxePLJGZdI
---
http://openwall.com/lists/oss-security/2014/07/02/5http://rhn.redhat.com/errata/RHSA-2014-0877.htmlhttp://secunia.com/advisories/59971http://secunia.com/advisories/60214http://www.debian.org/security/2014/dsa-2982http://www.securityfocus.com/bid/68341https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wDxePLJGZdI/WP7EasCJTA4Jhttp://openwall.com/lists/oss-security/2014/07/02/5http://rhn.redhat.com/errata/RHSA-2014-0877.htmlhttp://secunia.com/advisories/59971http://secunia.com/advisories/60214http://www.debian.org/security/2014/dsa-2982http://www.securityfocus.com/bid/68341https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wDxePLJGZdI/WP7EasCJTA4J
2014-07-07
Published