Vulnerability Name:

CVE-2013-0155 (CCN-81118)

Assigned:2012-12-06
Published:2013-01-10
Updated:2019-08-08
Summary:Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660 and CVE-2012-2694.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
3.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-264
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2013-0155

Source: MISC
Type: Third Party Advisory, US Government Resource
http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A

Source: CCN
Type: Tableau Software Web site
Ruby on Rails Vulnerabililty

Source: APPLE
Type: Mailing List, Third Party Advisory
APPLE-SA-2013-06-04-1

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2013:1904

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2013:1906

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2013:1907

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2014:0009

Source: CCN
Type: RHSA-2013-0154
Critical: Ruby on Rails security update

Source: REDHAT
Type: Third Party Advisory
RHSA-2013:0154

Source: CCN
Type: RHSA-2013-0155
Critical: Ruby on Rails security update

Source: REDHAT
Type: Third Party Advisory
RHSA-2013:0155

Source: CCN
Type: RHSA-2013-0582
Moderate: Red Hat OpenShift Enterprise 1.1.1 update

Source: CCN
Type: Ruby on Rails Web Site
Ruby on Rails

Source: CCN
Type: SA51753
Ruby on Rails XML Parameter Parsing Vulnerability

Source: CCN
Type: SA52367
Tableau Server Ruby on Rails XML Parameter Parsing Vulnerability

Source: CCN
Type: SA52369
Invensys Wonderware Intelligence Tableau Server Multiple Vulnerabilities

Source: CCN
Type: Apple Web site
About the security content of OS X Mountain Lion v10.8.4 and Security Update 2013-002

Source: CONFIRM
Type: Third Party Advisory
http://support.apple.com/kb/HT5784

Source: CCN
Type: IBM Security Bulletin 1626515
IBM Security Network Protection can be affected by vulnerabilities in Ruby on Rails (CVE-2012-2660, CVE-2012-2694, CVE-2013-0155, CVE-2013-0156, CVE-2012-6496, CVE-2012-3424, and CVE-2012-2695)

Source: DEBIAN
Type: Third Party Advisory
DSA-2609

Source: DEBIAN
Type: DSA-2609
rails -- SQL query manipulation

Source: CCN
Type: BID-57192
Ruby on Rails CVE-2013-0155 Unsafe SQL Query Generation Vulnerability

Source: XF
Type: UNKNOWN
rubyonrails-json-security-bypass(81118)

Source: CCN
Type: Google Groups: Ruby on Rails
Unsafe Query Generation Risk in Ruby on Rails (CVE-2013-0155)

Source: MLIST
Type: Third Party Advisory
[rubyonrails-security] 20130108 Unsafe Query Generation Risk in Ruby on Rails (CVE-2013-0155)

Source: CONFIRM
Type: Third Party Advisory
https://puppet.com/security/cve/cve-2013-0155

Vulnerable Configuration:Configuration 1:
  • cpe:/a:rubyonrails:rails:*:*:*:*:*:*:*:* (Version >= 3.2.0 and < 3.2.11)
  • OR cpe:/a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* (Version >= 3.0.0 and < 3.0.19)
  • OR cpe:/a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* (Version >= 3.1.0 and < 3.1.10)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:6.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:26225
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:26183
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:26181
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:26117
    P
    Security update for xen (Important)
    2021-09-02
    oval:org.opensuse.security:def:26119
    P
    Security update for file (Important)
    2021-09-02
    oval:org.opensuse.security:def:26108
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:26107
    P
    Security update for openssl-1_0_0 (Important)
    2021-08-24
    oval:org.opensuse.security:def:26106
    P
    Security update for libmspack (Moderate)
    2021-08-17
    oval:org.opensuse.security:def:26105
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:20130155
    V
    CVE-2013-0155
    2021-08-15
    oval:org.opensuse.security:def:36556
    P
    rubygem-actionpack-3_2-3.2.12-0.19.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36558
    P
    rubygem-activerecord-3_2-3.2.12-0.11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26214
    P
    Security update for wavpack (Important)
    2021-03-24
    oval:org.opensuse.security:def:26213
    P
    Security update for evolution-data-server (Moderate)
    2021-03-19
    oval:org.opensuse.security:def:26447
    P
    Security update for pdns (Important)
    2020-12-01
    oval:org.opensuse.security:def:26289
    P
    Security update for sane-backends (Important)
    2020-12-01
    oval:org.opensuse.security:def:27521
    P
    novell-ipsec-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26837
    P
    vte on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26843
    P
    xorg-x11 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26533
    P
    cups on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26390
    P
    Security update for ark (Low)
    2020-12-01
    oval:org.opensuse.security:def:27662
    P
    Security update for Ruby On Rails
    2020-12-01
    oval:org.opensuse.security:def:26883
    P
    dhcp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26823
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26790
    P
    ofed on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26449
    P
    Security update for nginx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26309
    P
    Security update for haproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:27627
    P
    Security update for IBM Java 7
    2020-12-01
    oval:org.opensuse.security:def:26839
    P
    wget on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26784
    P
    mono-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26639
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26392
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:26989
    P
    man on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26825
    P
    sysconfig on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26735
    P
    libMagickCore1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26555
    P
    glib2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26311
    P
    Security update for openstack-nova and openstack-neutron (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27554
    P
    rubygem-actionpack-3_2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26945
    P
    libdrm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26786
    P
    mutt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26682
    P
    cyrus-imapd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26498
    P
    Security update for nextcloud (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27519
    P
    nagios on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26931
    P
    krb5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26737
    P
    libadns1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26531
    P
    coolkey on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26417
    P
    Security update for Mozilla Thunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27556
    P
    rubygem-activerecord-3_2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26881
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26892
    P
    expat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26684
    P
    dbus-1-glib on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:17800
    P
    DSA-2609-1 rails - SQL query manipulation
    2014-06-23
    oval:com.ubuntu.precise:def:20130155000
    V
    CVE-2013-0155 on Ubuntu 12.04 LTS (precise) - high.
    2013-01-13
    BACK
    rubyonrails rails *
    rubyonrails ruby on rails *
    rubyonrails ruby on rails *
    debian debian linux 6.0