CVE-2012-2695

high
Published 2017-10-24 · Modified 2025-01-21
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

activerecord vulnerable to SQL Injection

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsactiverecord<~> 3.0.14~> 3.0.14
ruby RubyGemsactiverecord>=3.0.0.beta,<3.0.143.0.14
ruby RubyGemsactiverecord>=3.1.0,<3.1.63.1.6
ruby RubyGemsactiverecord>=3.2.0,<3.2.63.2.6
ruby RubyGemsactiverecord<2.3.152.3.15

Application impact

VendorProductVersionsFixed
rubyonrailsrails3.0.0
rubyonrailsrails3.0.1
rubyonrailsrails3.0.2
rubyonrailsrails3.0.3
rubyonrailsrails3.0.4
rubyonrailsrails3.0.5
rubyonrailsrails3.0.6
rubyonrailsrails3.0.7
rubyonrailsrails3.0.8
rubyonrailsrails3.0.9
rubyonrailsrails3.0.10
rubyonrailsrails3.0.11
rubyonrailsrails3.0.12
rubyonrailsrails3.0.13
rubyonrailsruby_on_rails{"endIncluding":"3.0.13"}
rubyonrailsruby_on_rails3.0.4
rubyonrailsrails3.1.0
rubyonrailsrails3.1.1
rubyonrailsrails3.1.2
rubyonrailsrails3.1.3
rubyonrailsrails3.1.4
rubyonrailsrails3.1.5
rubyonrailsrails3.2.0
rubyonrailsrails3.2.1
rubyonrailsrails3.2.2
rubyonrailsrails3.2.3
rubyonrailsrails3.2.4
rubyonrailsrails3.2.5

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.