V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2013-6417
DEB
Medium

actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences i…

CVSS
6.4
Medium
EPSS
0.02
p81
Published
2013-01-01
Updated
2013-01-01
Description

actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request that leverages (1) third-party Rack middleware or (2) custom Rack middleware. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-0155.

Tags · CWE
SQLi
CWE-264
CWE-89
CAPEC-7
CAPEC-66
CAPEC-108
CAPEC-109
CAPEC-110
CAPEC-470
Affected products
CfmePostgresql92-postgresqlPrinceRailsRailsRailsRailsRailsRailsRailsRailsRailsRailsRails-3.2Rails-4.0Ruby-actionpack-2.3Ruby-actionpack-3.2Ruby-actionpack-3.2Ruby-activerecord-3.2Ruby-activesupport-3.2
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Timeline
2013-01-01
Published
2013-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.024 · p81
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
cfmeTracked
postgresql92-postgresqlTracked
princeTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
railsTracked
rails-3.2Tracked
rails-4.0Tracked
ruby-actionpack-2.3Tracked
ruby-actionpack-3.2Tracked
ruby-actionpack-3.2Tracked
ruby-activerecord-3.2Tracked
ruby-activesupport-3.2Tracked
Showing first 20 of 27
Source databases
DEB
CVE
RED
UBU