CVE-2013-0155
Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass…
Does this matter?
Lower severity and a low EPSS score (8.24%). Track it; it rarely justifies an emergency change on its own.
Description
Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660 and CVE-2012-2694.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 8.24% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- rubyonrails/rails · rubyonrails/ruby on rails · debian/debian linux
- Source
- secalert@redhat.com
References
- http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01AThird Party Advisory, US Government Resource
- http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00081.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00082.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00003.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0154.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0155.htmlThird Party Advisory
- http://support.apple.com/kb/HT5784Third Party Advisory
- http://www.debian.org/security/2013/dsa-2609Third Party Advisory
- https://groups.google.com/group/rubyonrails-security/msg/bc6f13dafe130ee9?dmode=source&output=gplainThird Party Advisory
- https://puppet.com/security/cve/cve-2013-0155Third Party Advisory
- http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01AThird Party Advisory, US Government Resource
- http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00081.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00082.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00003.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0154.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0155.htmlThird Party Advisory
- http://support.apple.com/kb/HT5784Third Party Advisory
- http://www.debian.org/security/2013/dsa-2609Third Party Advisory
- https://groups.google.com/group/rubyonrails-security/msg/bc6f13dafe130ee9?dmode=source&output=gplainThird Party Advisory
- https://puppet.com/security/cve/cve-2013-0155Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.