sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.
{
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"nvd_published_at": null,
"github_reviewed": true,
"github_reviewed_at": "2020-06-10T18:28:37Z"
}