Release date:
Updated on:
Affected Systems:
Ruby on Rails 3.2.x
Ruby on Rails 3.1.x
Ruby on Rails 3.0.x
Ruby on Rails 2.3.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2012-2694, CVE-2012-2695
Ruby on Rails (RoR or Rails) is an open-source Web application framework written in Ruby. It is developed in strict accordance with the MVC structure.
Versions earlier than Ruby on Rails 3.2.6, 3.1.6, and 3.0.14 use incorrectly verified input in SQL queries. These inputs are passed to the Active Record interface through nested query parameters, inject SQL code to perform SQL queries. There IS also a vulnerability in Parameter Parsing Rack when ActionPack IS used. You can insert "is null" to SQL query.
<* Source: Ernie Miller
Link: http://secunia.com/advisories/49457/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ruby on Rails
-------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.rubyonrails.com/