Moderate severityNVD Advisory· Published Feb 20, 2014· Updated Apr 29, 2026
CVE-2014-0080
CVE-2014-0080
Description
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3, and 4.1.0.beta1, when PostgreSQL is used, allows remote attackers to execute "add data" SQL commands via vectors involving \ (backslash) characters that are not properly handled in operations on array columns.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
activerecordRubyGems | >= 4.0.0, < 4.0.3 | 4.0.3 |
activerecordRubyGems | >= 4.1.0.beta1, < 4.1.0.beta2 | 4.1.0.beta2 |
Affected products
12cpe:2.3:a:rubyonrails:rails:4.0.0:-:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:rubyonrails:rails:4.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.0.0:beta:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.0.1:-:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.0.1:rc1:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.0.1:rc2:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.0.1:rc3:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.0.1:rc4:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:rubyonrails:rails:4.1.0:beta1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- github.com/advisories/GHSA-hqf9-rc9j-5fmjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-0080ghsaADVISORY
- openwall.com/lists/oss-security/2014/02/18/9nvdWEB
- github.com/rails/rails/tree/main/activerecordghsaPACKAGE
- github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord/CVE-2014-0080.ymlghsaWEB
- web.archive.org/web/20210301004521/https://groups.google.com/forum/message/rawghsaWEB
- groups.google.com/forum/message/rawnvd
News mentions
0No linked articles in our index yet.