Ruby on Rails 'activerecord 'SQL Injection Vulnerability (CVE-2014-3483)
Release date:
Updated on:
Affected Systems:
Ruby on Rails
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68341
CVE (CAN) ID: CVE-2014-3483
Ruby on Rails (RoR or Rails) is an open-source Web application framework written in Ruby. It is developed in strict accordance with the MVC structure.
The SQL injection vulnerability exists in 'range' references of Ruby on Rails 4.0.0 to 4.1.2. After successful exploitation, remote attackers can execute unauthorized database operations.
<* Source: Sean Griffin in
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ruby on Rails
-------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.rubyonrails.com/
This article permanently updates the link address: