CVE-2017-17917
published 2017-12-29CVE-2017-17917: SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id'…
PriorityP346high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.28%
81.3th percentile
SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | — | — |
| rubyonrails | rails | <= 5.1.4 | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vqpc-h5g8-fhrw: ** DISPUTED ** SQL injection vulnerability in the 'where' method in Ruby on Rails 5
ghsa_unreviewed·2022-05-14
CVE-2017-17917 [HIGH] CWE-89 GHSA-vqpc-h5g8-fhrw: ** DISPUTED ** SQL injection vulnerability in the 'where' method in Ruby on Rails 5
** DISPUTED ** SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input.
OSV
CVE-2017-17917: SQL injection vulnerability in the 'where' method in Ruby on Rails 5
osv·2017-12-29·CVSS 8.1
CVE-2017-17917 [HIGH] CVE-2017-17917: SQL injection vulnerability in the 'where' method in Ruby on Rails 5
SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
OSV
CVE-2017-17917: ** DISPUTED ** SQL injection vulnerability in the 'where' method in Ruby on Rails 5
osv·2017-12-29·CVSS 8.1
CVE-2017-17917 [HIGH] CVE-2017-17917: ** DISPUTED ** SQL injection vulnerability in the 'where' method in Ruby on Rails 5
** DISPUTED ** SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input.
Debian
CVE-2017-17917: rails - SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and ear...
vendor_debian·2017·CVSS 8.1
CVE-2017-17917 [HIGH] CVE-2017-17917: rails - SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and ear...
SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-12-29
Published