CVE-2012-2695

Ruby on Rails <3.0.14, <3.1.x <3.1.6, <3.2.x <3.2.6 - SQL Injection

Title source: llm
STIX 2.1

Description

The Active Record component in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that leverage improper handling of nested hashes, a related issue to CVE-2012-2661.

References (6)

Core 6
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0154.html
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2012-08/msg00046.html

Scores

EPSS 0.0064
EPSS Percentile 70.7%

Details

CWE
CWE-89
Status published
Products (17)
rubygems/activerecord 3.0.0.beta - 3.0.14RubyGems
rubyonrails/rails 3.0.0 (7 CPE variants)
rubyonrails/rails 3.0.1 (2 CPE variants)
rubyonrails/rails 3.0.2 (2 CPE variants)
rubyonrails/rails 3.0.3
rubyonrails/rails 3.0.4 rc1
rubyonrails/rails 3.0.5 (2 CPE variants)
rubyonrails/rails 3.0.6 (3 CPE variants)
rubyonrails/rails 3.0.7 (3 CPE variants)
rubyonrails/rails 3.0.8 (5 CPE variants)
... and 7 more
Published Jun 22, 2012
Tracked Since Feb 18, 2026