Release date:
Updated on: 2012-06-01
Affected Systems:
Ruby on Rails 3.x
Unaffected system:
Ruby on Rails 3.2.4
Ruby on Rails 3.1.5
Ruby on Rails 3.0.13
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53753
CVE (CAN) ID: CVE-2012-2661
Ruby on Rails (RoR or Rails) is an open-source Web application framework written in Ruby. It is developed in strict accordance with the MVC structure.
The SQL injection vulnerability exists in the implementation of Ruby on Rails 3.2.4, 3.1.5, and 3.0.13 activity records to process nested query parameters, attackers can exploit this vulnerability to inject specific SQL statements into SQL queries of applications by specially crafted requests to control applications, access or modify data, or exploit other vulnerabilities in lower-layer databases.
<* Source: Ben Murphy
Link: http://seclists.org/oss-sec/2012/q2/448
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ruby on Rails
-------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.rubyonrails.com/