{"id":"GHSA-r8fh-hq2p-7qhq","summary":"Active Record contains SQL Injection via improper range quoting","details":"SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.","aliases":["CVE-2014-3483"],"modified":"2024-11-29T05:28:07.785614Z","published":"2017-10-24T18:33:36Z","database_specific":{"nvd_published_at":"2014-07-07T11:01:30Z","cwe_ids":["CWE-89"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:54:02Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3483"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord/CVE-2014-3483.yml"},{"type":"WEB","url":"https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wDxePLJGZdI/WP7EasCJTA4J"},{"type":"WEB","url":"https://web.archive.org/web/20200228150648/http://www.securityfocus.com/bid/68341"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2014/07/02/5"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0877.html"},{"type":"WEB","url":"http://www.debian.org/security/2014/dsa-2982"}],"affected":[{"package":{"name":"activerecord","ecosystem":"RubyGems","purl":"pkg:gem/activerecord"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.7"}]}],"versions":["4.0.0","4.0.1","4.0.1.rc1","4.0.1.rc2","4.0.1.rc3","4.0.1.rc4","4.0.2","4.0.3","4.0.4","4.0.4.rc1","4.0.5","4.0.6","4.0.6.rc1","4.0.6.rc2","4.0.6.rc3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-r8fh-hq2p-7qhq/GHSA-r8fh-hq2p-7qhq.json"}},{"package":{"name":"activerecord","ecosystem":"RubyGems","purl":"pkg:gem/activerecord"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"4.1.3"}]}],"versions":["4.1.0","4.1.1","4.1.2","4.1.2.rc1","4.1.2.rc2","4.1.2.rc3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-r8fh-hq2p-7qhq/GHSA-r8fh-hq2p-7qhq.json"}}],"schema_version":"1.9.0"}