Publish GHSA-3crr-9vmg-864v

This commit is contained in:
advisory-database[bot]
2023-03-14 22:13:16 +00:00
parent 2b7b73b7dc
commit ca96da4c20
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3crr-9vmg-864v",
"modified": "2023-02-13T20:48:44Z",
"modified": "2023-03-14T22:11:55Z",
"published": "2017-10-24T18:33:37Z",
"aliases": [
"CVE-2013-1854"
],
"summary": "Improper Input Validation in activerecord",
"summary": "Improper Input Validation in Active Record",
"details": "The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.",
"severity": [
@@ -91,10 +91,6 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=921329"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-3crr-9vmg-864v"
},
{
"type": "WEB",
"url": "https://groups.google.com/group/ruby-security-ann/msg/34e0d780b04308de?dmode=source&output=gplain"