CVE-2014-3483
N/A
N/A
Summary
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://rhn.redhat.com/errata/RHSA-2014-0877.html
- http://secunia.com/advisories/59971
- http://openwall.com/lists/oss-security/2014/07/02/5
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wDxePLJGZdI/WP7EasCJTA4J
- http://secunia.com/advisories/60214
- http://www.debian.org/security/2014/dsa-2982
- http://www.securityfocus.com/bid/68341
References
- http://rhn.redhat.com/errata/RHSA-2014-0877.html
- http://secunia.com/advisories/59971
- http://openwall.com/lists/oss-security/2014/07/02/5
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wDxePLJGZdI/WP7EasCJTA4J
- http://secunia.com/advisories/60214
- http://www.debian.org/security/2014/dsa-2982
- http://www.securityfocus.com/bid/68341
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.