CVE-2014-3483

Description

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.25

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-3483 are fixed in Ruby-activerecord 4.0.7Windows
Vulnerabilities CVE-2014-3483 are fixed in Ruby-activerecord 4.1.3Windows
Vulnerabilities CVE-2014-3483 are fixed in Ruby-activerecord for Linux 4.0.7Linux
Vulnerabilities CVE-2014-3483 are fixed in Ruby-activerecord for Linux 4.1.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234