GHSA-m8h6-m9p5-p2f8

Suggest an improvement
Source
https://github.com/advisories/GHSA-m8h6-m9p5-p2f8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-m8h6-m9p5-p2f8/GHSA-m8h6-m9p5-p2f8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m8h6-m9p5-p2f8
Withdrawn
2020-06-16T21:45:29Z
Published
2018-08-13T20:49:01Z
Modified
2024-12-02T05:54:35Z
Summary
Moderate severity vulnerability that affects activerecord
Details

Withdrawn, accidental duplicate publish.

Active Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660, CVE-2012-2694, and CVE-2013-0155.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T21:45:29Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

RubyGems / activerecord

Package

Name
activerecord
Purl
pkg:gem/activerecord

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
4.2.7.1

Affected versions

4.*
4.2.0
4.2.1.rc1
4.2.1.rc2
4.2.1.rc3
4.2.1.rc4
4.2.1
4.2.2
4.2.3.rc1
4.2.3
4.2.4.rc1
4.2.4
4.2.5.rc1
4.2.5.rc2
4.2.5
4.2.5.1
4.2.5.2
4.2.6.rc1
4.2.6
4.2.7.rc1
4.2.7

Database specific

last_known_affected_version_range
"<= 4.2.7.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-m8h6-m9p5-p2f8/GHSA-m8h6-m9p5-p2f8.json"