VYPR
Moderate severityNVD Advisory· Published Feb 20, 2014· Updated Apr 29, 2026

CVE-2014-0080

CVE-2014-0080

Description

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3, and 4.1.0.beta1, when PostgreSQL is used, allows remote attackers to execute "add data" SQL commands via vectors involving \ (backslash) characters that are not properly handled in operations on array columns.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
activerecordRubyGems
>= 4.0.0, < 4.0.34.0.3
activerecordRubyGems
>= 4.1.0.beta1, < 4.1.0.beta24.1.0.beta2

Affected products

12
  • Rubyonrails/Rails11 versions
    cpe:2.3:a:rubyonrails:rails:4.0.0:-:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:rubyonrails:rails:4.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:4.0.0:beta:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:4.0.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:4.0.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:4.0.1:-:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:4.0.1:rc1:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:4.0.1:rc2:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:4.0.1:rc3:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:4.0.1:rc4:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:4.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:rubyonrails:rails:4.1.0:beta1:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 4.0.0, < 4.0.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.