Back

CRITICAL

rubygem-activerecord: Data-type injection attacks due absent database column data type (input vs stored value) check

Published Apr 22, 2013

Description

The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

Affected products

Remediation

Red Hat statement

Not a security issue. This issue is due to the handling of data types when passing data between rubygem-activerecord and MySQL. Applications that use rubygem-activerecord and MySQL may be affected if written in a way that exposes the issue, however any flaw would be specific to that application. For further information, please refer to https://bugzilla.redhat.com/show_bug.cgi?id=954365#c5

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 22, 2013
Updated Aug 6, 2024
Reserved Apr 21, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Feb 7, 2013
GHSA-F57C-HX33-HVH8