Description
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request that leverages (1) third-party Rack middleware or (2) custom Rack middleware. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-0155.
Remediation
References
Related Vulnerabilities
WordPress Plugin WebP Converter for Media Cross-Site Request Forgery (1.0.2)
MySQL Other Vulnerability (CVE-2010-3683)
WordPress Plugin Windsor Strava Athlete Unspecified Vulnerability (1.3.5)
Jetty Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-22201)
Atlassian Jira Incorrect Default Permissions Vulnerability (CVE-2019-20106)