Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2012-2661
HistoryJun 22, 2012 - 2:55 p.m.

CVE-2012-2661

2012-06-2214:55:01
Debian Security Bug Tracker
security-tracker.debian.org
26

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.133 Low

EPSS

Percentile

95.6%

The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that leverage unintended recursion, a related issue to CVE-2012-2695.

OSVersionArchitecturePackageVersionFilename
Debian12allrails<Β 2:6.1.7.3+dfsg-2~deb12u1rails_2:6.1.7.3+dfsg-2~deb12u1_all.deb
Debian11allrails<Β 2:6.0.3.7+dfsg-2+deb11u2rails_2:6.0.3.7+dfsg-2+deb11u2_all.deb
Debian999allrails<Β 2:6.1.7.3+dfsg-3rails_2:6.1.7.3+dfsg-3_all.deb
Debian13allrails<Β 2:6.1.7.3+dfsg-3rails_2:6.1.7.3+dfsg-3_all.deb

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.133 Low

EPSS

Percentile

95.6%