GHSA-h6w6-xmqv-7q78

Suggest an improvement
Source
https://github.com/advisories/GHSA-h6w6-xmqv-7q78
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-h6w6-xmqv-7q78/GHSA-h6w6-xmqv-7q78.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h6w6-xmqv-7q78
Aliases
Published
2017-10-24T18:33:38Z
Modified
2025-11-03T14:13:18Z
Summary
activerecord vulnerable to SQL Injection
Details

Multiple SQL injection vulnerabilities in the quote_table_name method in the ActiveRecord adapters in activerecord/lib/active_record/connection_adapters/ in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allow remote attackers to execute arbitrary SQL commands via a crafted column name.

Database specific
{
    "cwe_ids":  [
        "CWE-89"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T21:39:17Z",
    "nvd_published_at":  "2011-08-29T18:55:01Z",
    "severity":  "HIGH"
}
References

Affected packages

RubyGems / activerecord

Package

Name
activerecord
Purl
pkg:gem/activerecord

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.3.13

Affected versions

2.*
2.0.0
2.0.1
2.0.2
2.0.4
2.0.5
2.1.0
2.1.1
2.1.2
2.2.2
2.2.3
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8.pre1
2.3.8
2.3.9.pre
2.3.9
2.3.10
2.3.11
2.3.12

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-h6w6-xmqv-7q78/GHSA-h6w6-xmqv-7q78.json"

RubyGems / activerecord

Package

Name
activerecord
Purl
pkg:gem/activerecord

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0.beta
Fixed
3.0.10

Affected versions

3.*
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.0.beta4
3.0.0.rc
3.0.0.rc2
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4.rc1
3.0.4
3.0.5.rc1
3.0.5
3.0.6.rc1
3.0.6.rc2
3.0.6
3.0.7.rc1
3.0.7.rc2
3.0.7
3.0.8.rc1
3.0.8.rc2
3.0.8.rc4
3.0.8
3.0.9.rc1
3.0.9.rc3
3.0.9.rc4
3.0.9.rc5
3.0.9
3.0.10.rc1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-h6w6-xmqv-7q78/GHSA-h6w6-xmqv-7q78.json"

RubyGems / activerecord

Package

Name
activerecord
Purl
pkg:gem/activerecord

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.1.0.beta1
Fixed
3.1.0.rc5

Affected versions

3.*
3.1.0.beta1
3.1.0.rc1
3.1.0.rc2
3.1.0.rc3
3.1.0.rc4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-h6w6-xmqv-7q78/GHSA-h6w6-xmqv-7q78.json"