CVE-2016-6317
published 2016-09-07CVE-2016-6317: Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the…
PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
3.90%
89.2th percentile
Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660, CVE-2012-2694, and CVE-2013-0155.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activerecord_project | activerecord | >= 4.2.0 < 4.2.7.1 | 4.2.7.1 |
| debian | rails | < rails 2:4.2.7.1-1 (bookworm) | rails 2:4.2.7.1-1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | >= 0 < 2:4.2.7.1-1 | 2:4.2.7.1-1 |
| rubyonrails | rails | >= 0 < 2:4.2.7.1-1 | 2:4.2.7.1-1 |
| rubyonrails | rails | >= 0 < 2:4.2.7.1-1 | 2:4.2.7.1-1 |
| rubyonrails | rails | >= 0 < 2:4.2.7.1-1 | 2:4.2.7.1-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
ghsa6.4MEDIUM
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
ActiveRecord in Ruby on Rails allows database-query bypass
ghsa·2017-10-24·CVSS 6.4
CVE-2016-6317 [MEDIUM] CWE-284 ActiveRecord in Ruby on Rails allows database-query bypass
ActiveRecord in Ruby on Rails allows database-query bypass
Active Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660, CVE-2012-2694, and CVE-2013-0155.
OSV
ActiveRecord in Ruby on Rails allows database-query bypass
osv·2017-10-24·CVSS 6.4
CVE-2016-6317 [MEDIUM] ActiveRecord in Ruby on Rails allows database-query bypass
ActiveRecord in Ruby on Rails allows database-query bypass
Active Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660, CVE-2012-2694, and CVE-2013-0155.
OSV
CVE-2016-6317: Action Record in Ruby on Rails 4
osv·2016-09-07·CVSS 6.4
CVE-2016-6317 [MEDIUM] CVE-2016-6317: Action Record in Ruby on Rails 4
Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660, CVE-2012-2694, and CVE-2013-0155.
Red Hat
rubygem-activerecord: unsafe query generation in Active Record
vendor_redhat·2016-08-11·CVSS 6.4
CVE-2016-6317 [MEDIUM] CWE-20 rubygem-activerecord: unsafe query generation in Active Record
rubygem-activerecord: unsafe query generation in Active Record
Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660, CVE-2012-2694, and CVE-2013-0155.
A flaw was found in the way Active Record handled certain special values in dynamic finders and relations. If a Ruby on Rails application performed JSON parameter parsing, a remote attacker could possibly manipulate search conditions in SQL queries generated by the application.
Package:
Debian
CVE-2016-6317: rails - Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider d...
vendor_debian·2016·CVSS 6.4
CVE-2016-6317 [MEDIUM] CVE-2016-6317: rails - Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider d...
Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660, CVE-2012-2694, and CVE-2013-0155.
Scope: local
bookworm: resolved (fixed in 2:4.2.7.1-1)
bullseye: resolved (fixed in 2:4.2.7.1-1)
forky: resolved (fixed in 2:4.2.7.1-1)
sid: resolved (fixed in 2:4.2.7.1-1)
trixie: resolved (fixed in 2:4.2.7.1-1)
No detection rules found.
No public exploits indexed.
HackerOne
Unsafe Query Generation (CVE-2012-2660, CVE-2012-2694 and CVE-2013-0155) mitigation bypass
hackerone·2018-02-07·CVSS 6.4
CVE-2012-2660 [MEDIUM] Unsafe Query Generation (CVE-2012-2660, CVE-2012-2694 and CVE-2013-0155) mitigation bypass
Unsafe Query Generation (CVE-2012-2660, CVE-2012-2694 and CVE-2013-0155) mitigation bypass
# Unsafe Query Generation Risk in Active Record
There is a vulnerability when Active Record is used in conjunction with JSON
parameter parsing. This vulnerability has been assigned the CVE identifier
CVE-2016-6317. This vulnerability is similar to CVE-2012-2660, CVE-2012-2694
and CVE-2013-0155.
Versions Affected: >= 4.2.0
Not affected: = 5.0.0
Fixed Versions: 4.2.7.1
Impact
Due to the way Active Record interprets parameters in combination with the way that JSON parameters are parsed, it is possible for an attacker to issue unexpected database queries with "IS NULL" or empty where clauses. This issue does *not* let an attacker insert arbitrary values into an SQL query, however they can cause the
Bugzilla
CVE-2016-6316 rubygem-actionview: cross-site scripting flaw in Action View [fedora-all]
bugzilla·2016-08-12·CVSS 6.1
CVE-2016-6316 [MEDIUM] CVE-2016-6316 rubygem-actionview: cross-site scripting flaw in Action View [fedora-all]
CVE-2016-6316 rubygem-actionview: cross-site scripting flaw in Action View [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2016-6317 rubygem-activerecord: unsafe query generation in Active Record [fedora-all]
bugzilla·2016-08-12·CVSS 7.5
CVE-2016-6317 [HIGH] CVE-2016-6317 rubygem-activerecord: unsafe query generation in Active Record [fedora-all]
CVE-2016-6317 rubygem-activerecord: unsafe query generation in Active Record [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2016-6317 rubygem-activerecord: unsafe query generation in Active Record
bugzilla·2016-08-08·CVSS 7.5
CVE-2016-6317 [HIGH] CVE-2016-6317 rubygem-activerecord: unsafe query generation in Active Record
CVE-2016-6317 rubygem-activerecord: unsafe query generation in Active Record
The following flaw was found in Active Record:
Due to the way Active Record interprets parameters in combination with the way that JSON parameters are parsed, it is possible for an attacker to issue unexpected database queries with "IS NULL" or empty where clauses. This issue does *not* let an attacker insert arbitrary values into an SQL query, however they can cause the query to check for NULL or eliminate a WHERE clause when most users wouldn't expect it.
This issue only affects the 4.2.x versions of Active Record.
Discussion:
Acknowledgments:
Name: the Ruby on Rails project
Upstream: joernchen (Phenoelit)
---
Created attachment 1188641
4-2-unsafe-query-generation.patch
---
Created rubygem-activerecord
http://rhn.redhat.com/errata/RHSA-2016-1855.htmlhttp://weblog.rubyonrails.org/2016/8/11/Rails-5-0-0-1-4-2-7-2-and-3-2-22-3-have-been-released/http://www.openwall.com/lists/oss-security/2016/08/11/4http://www.securityfocus.com/bid/92434https://groups.google.com/forum/#%21topic/ruby-security-ann/WccgKSKiPZAhttp://rhn.redhat.com/errata/RHSA-2016-1855.htmlhttp://weblog.rubyonrails.org/2016/8/11/Rails-5-0-0-1-4-2-7-2-and-3-2-22-3-have-been-released/http://www.openwall.com/lists/oss-security/2016/08/11/4http://www.securityfocus.com/bid/92434https://groups.google.com/forum/#%21topic/ruby-security-ann/WccgKSKiPZA
2016-09-07
Published