CVE-2012-2660

medium
Published 2017-10-24 · Modified 2025-01-22
CVSS v3
CVSS v2
6.4
VIR risk
6.4

Description

Action Pack contains database-query restrictions bypass

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsactionpack<~> 3.0.13~> 3.0.13
ruby RubyGemsactiverecord<~> 3.0.13~> 3.0.13
ruby RubyGemsactionpack>=3.0.0.beta,<3.0.133.0.13
ruby RubyGemsactionpack>=3.1.0,<3.1.53.1.5
ruby RubyGemsactionpack>=3.2.0,<3.2.43.2.4
ruby RubyGemsactionpack<2.3.162.3.16

Application impact

VendorProductVersionsFixed
rubyonrailsrails3.0.0
rubyonrailsrails3.0.1
rubyonrailsrails3.0.2
rubyonrailsrails3.0.3
rubyonrailsrails3.0.4
rubyonrailsrails3.0.5
rubyonrailsrails3.0.6
rubyonrailsrails3.0.7
rubyonrailsrails3.0.8
rubyonrailsrails3.0.9
rubyonrailsrails3.0.10
rubyonrailsrails3.0.11
rubyonrailsrails3.0.12
rubyonrailsrails3.0.13
rubyonrailsruby_on_rails3.0.4
rubyonrailsrails3.1.0
rubyonrailsrails3.1.1
rubyonrailsrails3.1.2
rubyonrailsrails3.1.3
rubyonrailsrails3.1.4
rubyonrailsrails3.1.5
rubyonrailsrails3.2.0
rubyonrailsrails3.2.1
rubyonrailsrails3.2.2
rubyonrailsrails3.2.3
rubyonrailsrails3.2.4

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.