CVE-2012-2695

The Active Record component in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that leverage improper handling of nested hashes, a related issue to CVE-2012-2661.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
VendorProductVersion
rubyonrailsrails
3.0.0
rubyonrailsrails
3.0.0:beta
rubyonrailsrails
3.0.0:beta2
rubyonrailsrails
3.0.0:beta3
rubyonrailsrails
3.0.0:beta4
rubyonrailsrails
3.0.0:rc
rubyonrailsrails
3.0.0:rc2
rubyonrailsrails
3.0.1
rubyonrailsrails
3.0.1:pre
rubyonrailsrails
3.0.2
rubyonrailsrails
3.0.2:pre
rubyonrailsrails
3.0.3
rubyonrailsrails
3.0.4:rc1
rubyonrailsrails
3.0.5
rubyonrailsrails
3.0.5:rc1
rubyonrailsrails
3.0.6
rubyonrailsrails
3.0.6:rc1
rubyonrailsrails
3.0.6:rc2
rubyonrailsrails
3.0.7
rubyonrailsrails
3.0.7:rc1
rubyonrailsrails
3.0.7:rc2
rubyonrailsrails
3.0.8
rubyonrailsrails
3.0.8:rc1
rubyonrailsrails
3.0.8:rc2
rubyonrailsrails
3.0.8:rc3
rubyonrailsrails
3.0.8:rc4
rubyonrailsrails
3.0.9
rubyonrailsrails
3.0.9:rc1
rubyonrailsrails
3.0.9:rc2
rubyonrailsrails
3.0.9:rc3
rubyonrailsrails
3.0.9:rc4
rubyonrailsrails
3.0.9:rc5
rubyonrailsrails
3.0.10
rubyonrailsrails
3.0.10:rc1
rubyonrailsrails
3.0.11
rubyonrailsrails
3.0.12
rubyonrailsrails
3.0.12:rc1
rubyonrailsrails
3.0.13:rc1
rubyonrailsruby_on_rails
𝑥
≤ 3.0.13
rubyonrailsruby_on_rails
3.0.4
rubyonrailsrails
3.1.0
rubyonrailsrails
3.1.0:beta1
rubyonrailsrails
3.1.0:rc1
rubyonrailsrails
3.1.0:rc2
rubyonrailsrails
3.1.0:rc3
rubyonrailsrails
3.1.0:rc4
rubyonrailsrails
3.1.0:rc5
rubyonrailsrails
3.1.0:rc6
rubyonrailsrails
3.1.0:rc7
rubyonrailsrails
3.1.0:rc8
rubyonrailsrails
3.1.1
rubyonrailsrails
3.1.1:rc1
rubyonrailsrails
3.1.1:rc2
rubyonrailsrails
3.1.1:rc3
rubyonrailsrails
3.1.2
rubyonrailsrails
3.1.2:rc1
rubyonrailsrails
3.1.2:rc2
rubyonrailsrails
3.1.3
rubyonrailsrails
3.1.4
rubyonrailsrails
3.1.4:rc1
rubyonrailsrails
3.1.5
rubyonrailsrails
3.1.5:rc1
rubyonrailsrails
3.2.0
rubyonrailsrails
3.2.0:rc1
rubyonrailsrails
3.2.0:rc2
rubyonrailsrails
3.2.1
rubyonrailsrails
3.2.2
rubyonrailsrails
3.2.2:rc1
rubyonrailsrails
3.2.3
rubyonrailsrails
3.2.3:rc1
rubyonrailsrails
3.2.3:rc2
rubyonrailsrails
3.2.4
rubyonrailsrails
3.2.4:rc1
rubyonrailsrails
3.2.5
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby-activerecord-3.2
precise
dne
oneiric
dne
natty
dne
lucid
dne
hardy
dne