GHSA-3crr-9vmg-864v

Source
https://github.com/advisories/GHSA-3crr-9vmg-864v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-3crr-9vmg-864v/GHSA-3crr-9vmg-864v.json
Aliases
  • CVE-2013-1854
Published
2017-10-24T18:33:37Z
Modified
2024-02-16T08:11:01.166448Z
Details

The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.

References

Affected packages

RubyGems / activerecord

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3.0
Fixed
2.3.18

Affected versions

2.*

2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8.pre1
2.3.8
2.3.9.pre
2.3.9
2.3.10
2.3.11
2.3.12
2.3.14
2.3.15
2.3.16
2.3.17

RubyGems / activerecord

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.1.0
Fixed
3.1.12

Affected versions

3.*

3.1.0
3.1.1.rc1
3.1.1.rc2
3.1.1.rc3
3.1.1
3.1.2.rc1
3.1.2.rc2
3.1.2
3.1.3
3.1.4.rc1
3.1.4
3.1.5.rc1
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
3.1.10
3.1.11

RubyGems / activerecord

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.0
Fixed
3.2.13

Affected versions

3.*

3.2.0
3.2.1
3.2.2.rc1
3.2.2
3.2.3.rc1
3.2.3.rc2
3.2.3
3.2.4.rc1
3.2.4
3.2.5
3.2.6
3.2.7.rc1
3.2.7
3.2.8.rc1
3.2.8.rc2
3.2.8
3.2.9.rc1
3.2.9.rc2
3.2.9.rc3
3.2.9
3.2.10
3.2.11
3.2.12
3.2.13.rc1
3.2.13.rc2