Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10727
HistoryJan 15, 2019 - 8:51 a.m.

Denial Of Service (DoS)

2019-01-1508:51:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

0.089 Low

EPSS

Percentile

94.6%

The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.

References