{"id":"GHSA-h6w6-xmqv-7q78","summary":"activerecord vulnerable to SQL Injection","details":"Multiple SQL injection vulnerabilities in the `quote_table_name` method in the ActiveRecord adapters in `activerecord/lib/active_record/connection_adapters/` in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allow remote attackers to execute arbitrary SQL commands via a crafted column name.","aliases":["CVE-2011-2930"],"modified":"2025-11-03T14:13:18.010693Z","published":"2017-10-24T18:33:38Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:39:17Z","nvd_published_at":"2011-08-29T18:55:01Z","cwe_ids":["CWE-89"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-2930"},{"type":"WEB","url":"https://github.com/rails/rails/commit/8a39f411dc3c806422785b1f4d5c7c9d58e4bf85"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=731438"},{"type":"PACKAGE","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord/CVE-2011-2930.yml"},{"type":"WEB","url":"http://groups.google.com/group/rubyonrails-security/msg/b1a85d36b0f9dd30?dmode=source&output=gplain"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065212.html"},{"type":"WEB","url":"http://weblog.rubyonrails.org/2011/8/16/ann-rails-3-1-0-rc6"},{"type":"WEB","url":"http://www.debian.org/security/2011/dsa-2301"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/08/17/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/08/19/11"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/08/20/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/08/22/13"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/08/22/14"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/08/22/5"}],"affected":[{"package":{"name":"activerecord","ecosystem":"RubyGems","purl":"pkg:gem/activerecord"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.3.13"}]}],"versions":["2.0.0","2.0.1","2.0.2","2.0.4","2.0.5","2.1.0","2.1.1","2.1.2","2.2.2","2.2.3","2.3.10","2.3.11","2.3.12","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.3.8","2.3.8.pre1","2.3.9","2.3.9.pre"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-h6w6-xmqv-7q78/GHSA-h6w6-xmqv-7q78.json"}},{"package":{"name":"activerecord","ecosystem":"RubyGems","purl":"pkg:gem/activerecord"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0.beta"},{"fixed":"3.0.10"}]}],"versions":["3.0.0","3.0.0.beta","3.0.0.beta2","3.0.0.beta3","3.0.0.beta4","3.0.0.rc","3.0.0.rc2","3.0.1","3.0.10.rc1","3.0.2","3.0.3","3.0.4","3.0.4.rc1","3.0.5","3.0.5.rc1","3.0.6","3.0.6.rc1","3.0.6.rc2","3.0.7","3.0.7.rc1","3.0.7.rc2","3.0.8","3.0.8.rc1","3.0.8.rc2","3.0.8.rc4","3.0.9","3.0.9.rc1","3.0.9.rc3","3.0.9.rc4","3.0.9.rc5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-h6w6-xmqv-7q78/GHSA-h6w6-xmqv-7q78.json"}},{"package":{"name":"activerecord","ecosystem":"RubyGems","purl":"pkg:gem/activerecord"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1.0.beta1"},{"fixed":"3.1.0.rc5"}]}],"versions":["3.1.0.beta1","3.1.0.rc1","3.1.0.rc2","3.1.0.rc3","3.1.0.rc4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-h6w6-xmqv-7q78/GHSA-h6w6-xmqv-7q78.json"}}],"schema_version":"1.9.0"}