actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly…
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks via a crafted request, as demonstrated by certain "['xyz', nil]" values, a related issue to CVE-2012-2660.
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as control elements or syntactic markers when they are sent to a downstream component.
https://cwe.mitre.org/data/definitions/138.html →Open in CWE collection →Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
https://cwe.mitre.org/data/definitions/264.html →Open in CWE collection →An attack of this type exploits a programs' vulnerabilities that allows an attacker's commands to be concatenated onto a legitimate command with the intent of targeting other resources such as the file system or database. The system that uses a filter or denylist input validation, as opposed to allowlist validation is vulnerable to an attacker who predicts delimiters (or combinations of delimiters) not present in the filter or denylist. As with other injection attacks, the attacker uses the command delimiter payload as an entry point to tunnel through the application and activate additional attacks through SQL queries, shell commands, network scanning, and so on.
https://capec.mitre.org/data/definitions/15.html →Open in CAPEC collection →https://capec.mitre.org/data/definitions/34.html →Open in CAPEC collection →
https://capec.mitre.org/data/definitions/105.html →Open in CAPEC collection →
| Product | Vendor | Status |
|---|---|---|
| converge-ui-devel | Tracked | |
| graphviz | Tracked | |
| openshift-console | Tracked | |
| openshift-origin-broker | Tracked | |
| openshift-origin-broker-util | Tracked | |
| openshift-origin-cartridge-cron-1.4 | Tracked | |
| openshift-origin-cartridge-diy-0.1 | Tracked | |
| openshift-origin-cartridge-haproxy-1.4 | Tracked | |
| openshift-origin-cartridge-jbosseap-6.0 | Tracked | |
| openshift-origin-cartridge-jbossews-1.0 | Tracked | |
| openshift-origin-cartridge-jenkins-1.4 | Tracked | |
| openshift-origin-cartridge-jenkins-client-1.4 | Tracked | |
| openshift-origin-cartridge-mysql-5.1 | Tracked | |
| openshift-origin-cartridge-perl-5.10 | Tracked | |
| openshift-origin-cartridge-php-5.3 | Tracked | |
| openshift-origin-cartridge-postgresql-8.4 | Tracked | |
| openshift-origin-cartridge-ruby-1.8 | Tracked | |
| openshift-origin-cartridge-ruby-1.9-scl | Tracked | |
| openshift-origin-msg-node-mcollective | Tracked | |
| php | Tracked |