CVE 2013-0155
Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660 and CVE-2012-2694.
Related bugs and status
CVE-2013-0155 (Candidate) is related to these bugs:
Bug #1100162: Unsafe Query Generation Risk in Ruby on Rails
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1100162 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-3.2 (Ubuntu) | Undecided | Fix Released |
Bug #1100188: Unsafe Query Generation Risk in Ruby on Rails
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-activerecord-3.2 (Ubuntu) | Undecided | Fix Released | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-activerecord-3.2 (Ubuntu Lucid) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-activerecord-3.2 (Ubuntu Oneiric) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-activerecord-3.2 (Ubuntu Quantal) | Undecided | Fix Released | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-activerecord-3.2 (Ubuntu Precise) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-activerecord-3.2 (Ubuntu Raring) | Undecided | Fix Released | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | rails (Ubuntu) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | rails (Ubuntu Lucid) | Undecided | Won't Fix | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | rails (Ubuntu Oneiric) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | rails (Ubuntu Precise) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | rails (Ubuntu Quantal) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | rails (Ubuntu Raring) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-activerecord-2.3 (Ubuntu) | Undecided | Fix Released | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-activerecord-2.3 (Ubuntu Lucid) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-activerecord-2.3 (Ubuntu Oneiric) | Undecided | Fix Released | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-activerecord-2.3 (Ubuntu Precise) | Undecided | Fix Released | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-activerecord-2.3 (Ubuntu Quantal) | Undecided | Fix Released | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-activerecord-2.3 (Ubuntu Raring) | Undecided | Fix Released | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-2.3 (Ubuntu) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-2.3 (Ubuntu Lucid) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-2.3 (Ubuntu Oneiric) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-2.3 (Ubuntu Precise) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-2.3 (Ubuntu Quantal) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-2.3 (Ubuntu Raring) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-3.2 (Ubuntu) | Undecided | Fix Released | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-3.2 (Ubuntu Lucid) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-3.2 (Ubuntu Oneiric) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-3.2 (Ubuntu Precise) | Undecided | Invalid | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-3.2 (Ubuntu Quantal) | Undecided | Fix Released | ||
1100188 | Unsafe Query Generation Risk in Ruby on Rails | ruby-actionpack-3.2 (Ubuntu Raring) | Undecided | Fix Released |
Bug #1100590: Upgrade to 2.3.15 for "extremely critical security fixes" (CVE-2013-0155) and (CVE-2013-0156)
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1100590 | Upgrade to 2.3.15 for "extremely critical security fixes" (CVE-2013-0155) and (CVE-2013-0156) | ruby-activesupport-2.3 (Ubuntu) | Undecided | In Progress |
See the
CVE page on Mitre.org
for more details.