605
VMScore

CVE-2017-17917

Published: 29/12/2017 Updated: 11/04/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and previous versions allows remote malicious users to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

Vulnerable Product Search on Vulmon Subscribe to Product

rubyonrails rails

Github Repositories

rails-cve-2017-17917 The project demonstrates the replication of a SQL injection vulnerability in the id parameter, and subsequently provides insights into mitigating and resolving this security issue wwwcvedetailscom/cve/CVE-2017-17917/?q=CVE-2017-17917 Stack: Ruby: 322 Rails: 708 Docker 2405 Docker-Compose 1292 PostgreSQL