CVE-2017-17919
29.12.2017, 16:29
SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
| Vendor | Product | Version |
|---|---|---|
| rubyonrails | ruby_on_rails | 𝑥 ≤ 5.1.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rails |
| ||||||||||||||||||||||||||||||||||
| rails-4.0 |
| ||||||||||||||||||||||||||||||||||
| ruby-actionpack-3.2 |
| ||||||||||||||||||||||||||||||||||
| ruby-activemodel-3.2 |
| ||||||||||||||||||||||||||||||||||
| ruby-activerecord-3.2 |
| ||||||||||||||||||||||||||||||||||
| ruby-activesupport-3.2 |
| ||||||||||||||||||||||||||||||||||
| ruby-rails-3.2 |
|