Ruby on Rails 'activerecord 'SQL Injection Vulnerability (CVE-2014-3482)
Release date:
Updated on:
Affected Systems:
Ruby on Rails
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68343
CVE (CAN) ID: CVE-2014-3482
Ruby on Rails (RoR or Rails) is an open-source Web application framework written in Ruby. It is developed in strict accordance with the MVC structure.
The 'bitstring' reference in Ruby on Rails 4.0.0 to 4.1.2 has the SQL injection vulnerability. After successful exploitation, remote attackers can perform unauthorized database operations.
<* Source: Sean Griffin in
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ruby on Rails
-------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.rubyonrails.com/
Important article: Ruby-Linux/Windows installation, code development, and Rails practice
Ruby on rails:
This article permanently updates the link address: