Release date:
Updated on: 2012-06-04
Affected Systems:
Ruby on Rails 3.x
Unaffected system:
Ruby on Rails 3.2.4
Ruby on Rails 3.1.5
Ruby on Rails 3.0.13
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53754
Cve id: CVE-2012-2660
Ruby on Rails (RoR or Rails) is an open-source Web application framework written in Ruby. It is developed in strict accordance with the MVC structure.
The SQL injection vulnerability exists in the implementation of activity records filtering nested query parameters in Ruby on Rails 3.2.4, 3.1.5, and 3.0.13. This vulnerability allows attackers to operate SQL queries and execute SQL injection attacks. When using ActionPack, there IS also a vulnerability in Parameter Parsing on Rack, which allows inserting "is null" into SQL queries.
<* Source: Ben Murphy
Link: http://seclists.org/oss-sec/2012/q2/449
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ruby on Rails
-------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.rubyonrails.com/