VDB

DEBIAN-CVE-2014-3482

DEBIAN-CVE-2014-3482 PUBLISHED CVSS 9.300000190734863 CRITICAL

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting.

Risk Scores

CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:14rails0, 0, 0
Debian:12rails0, 0, 0
Debian:11rails0, 0, 0
Debian:13rails0, 0, 0

Timeline

  • Jul 7, 2014 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›