Bugzilla – Bug 885610
VUL-0: CVE-2014-3483: rubygem-activerecord-4.0: SQL injection vulnerability in 'range' quoting
Last modified: 2014-07-29 08:49:58 UTC
CVE-2014-3483 An SQL injection flaw was found in the PostgreSQL adapter for Active Record. An attacker could possibly perform SQL injection attacks if a Ruby on Rails application performed queries against the range type. This issue affects versions 4.0.0 to 4.1.2. It is reported that versions earlier than 4.0 are not affected. References: https://groups.google.com/forum/#!topic/rubyonrails-security/wDxePLJGZdI https://bugzilla.redhat.com/show_bug.cgi?id=1114427 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3483 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3483
bugbot adjusting priority
openSUSE nor SLES ships rails 4. Closing it.