Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-6317


Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660, CVE-2012-2694, and CVE-2013-0155.


Published

2016-09-07T19:28:11.410

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-284
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rubyonrails rails 4.2.0 Yes
Application rubyonrails rails 4.2.0 Yes
Application rubyonrails rails 4.2.0 Yes
Application rubyonrails rails 4.2.0 Yes
Application rubyonrails rails 4.2.0 Yes
Application rubyonrails rails 4.2.0 Yes
Application rubyonrails rails 4.2.0 Yes
Application rubyonrails rails 4.2.0 Yes
Application rubyonrails rails 4.2.1 Yes
Application rubyonrails rails 4.2.1 Yes
Application rubyonrails rails 4.2.1 Yes
Application rubyonrails rails 4.2.1 Yes
Application rubyonrails rails 4.2.1 Yes
Application rubyonrails rails 4.2.2 Yes
Application rubyonrails rails 4.2.3 Yes
Application rubyonrails rails 4.2.3 Yes
Application rubyonrails rails 4.2.4 Yes
Application rubyonrails rails 4.2.4 Yes
Application rubyonrails rails 4.2.5 Yes
Application rubyonrails rails 4.2.5 Yes
Application rubyonrails rails 4.2.5 Yes
Application rubyonrails rails 4.2.5.1 Yes
Application rubyonrails rails 4.2.5.2 Yes
Application rubyonrails rails 4.2.6 Yes
Application rubyonrails rails 4.2.6 Yes
Application rubyonrails rails 4.2.7 Yes
Application rubyonrails rails 4.2.7 Yes

References