CVE-2012-2694

medium
Published 2017-10-24 · Modified 2025-01-20
CVSS v3
CVSS v2
4.3
VIR risk
4.3

Description

actionpack allows remote attackers to bypass database-query restrictions, perform NULL checks via crafted request

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsactionpack<~> 3.0.14~> 3.0.14
ruby RubyGemsactionpack>=3.0.13,<3.0.143.0.14
ruby RubyGemsactionpack>=3.1.0,<3.1.63.1.6
ruby RubyGemsactionpack>=3.2.0,<3.2.63.2.6

Application impact

VendorProductVersionsFixed
rubyonrailsrails3.0.0
rubyonrailsrails3.0.1
rubyonrailsrails3.0.2
rubyonrailsrails3.0.3
rubyonrailsrails3.0.4
rubyonrailsrails3.0.5
rubyonrailsrails3.0.6
rubyonrailsrails3.0.7
rubyonrailsrails3.0.8
rubyonrailsrails3.0.9
rubyonrailsrails3.0.10
rubyonrailsrails3.0.11
rubyonrailsrails3.0.12
rubyonrailsrails3.0.13
rubyonrailsruby_on_rails{"endIncluding":"3.0.13"}
rubyonrailsruby_on_rails3.0.4
rubyonrailsrails3.1.0
rubyonrailsrails3.1.1
rubyonrailsrails3.1.2
rubyonrailsrails3.1.3
rubyonrailsrails3.1.4
rubyonrailsrails3.1.5
rubyonrailsrails3.2.0
rubyonrailsrails3.2.1
rubyonrailsrails3.2.2
rubyonrailsrails3.2.3
rubyonrailsrails3.2.4
rubyonrailsrails3.2.5

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.