CVE-2017-17919: SQL Injection
DISPUTED SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-17919?
CVE-2017-17919 is a SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier.
How does CVE-2017-17919 work?
CVE-2017-17919 allows remote attackers to execute arbitrary SQL commands by exploiting the 'id desc' parameter in the 'order' method.
What is the severity of CVE-2017-17919?
CVE-2017-17919 has a severity rating of 8.1, which is considered high.
Is there a fix available for CVE-2017-17919?
To fix CVE-2017-17919, upgrade Ruby on Rails to a version higher than 5.1.4.
Where can I find more information about CVE-2017-17919?
You can find more information about CVE-2017-17919 at https://kay-malwarebenchmark.github.io/blog/ruby-on-rails-arbitrary-sql-injection/.