Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-2661
HistoryJun 22, 2012 - 12:00 a.m.

CVE-2012-2661

2012-06-2200:00:00
ubuntu.com
ubuntu.com
21

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.133 Low

EPSS

Percentile

95.6%

The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x
before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the
passing of request data to a where method in an ActiveRecord class, which
allows remote attackers to conduct certain SQL injection attacks via nested
query parameters that leverage unintended recursion, a related issue to
CVE-2012-2695.

Notes

Author Note
tyhicks Fixed in upstream version 3.2.4, 3.1.5, 3.0.13 2.3.x is not affected

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.133 Low

EPSS

Percentile

95.6%