CVE-2014-3482

EPSS 1.5%

ruby-activerecord-3.2 - security update

發布日:2017/10/24修改日:2026/3/9
也稱為:GHSA-mhwp-qhpc-h3jmDSA-2982-1DEBIAN-CVE-2014-3482

描述

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting.

受影響套件(3)

參考連結(8)