Back

HIGH

rubygem-activerecord: Denial of Service

Published Feb 9, 2023

Description

A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 64bit signed integer is provided to the PostgreSQL connection adapter, it will treat the target column type as numeric. Comparing integer values against numeric values can result in a slow sequential scan resulting in potential Denial of Service.

Affected products

Remediation

No remediation recorded yet.

References (16)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner hackerone
Published Feb 9, 2023
Updated Mar 25, 2025
Reserved Nov 1, 2022

CISA Vulnrichment

Updated Mar 25, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jan 20, 2023
Bugzilla 2164789

ENISA EUVD

Assigner hackerone
Published Feb 9, 2023
Updated Mar 25, 2025