Critical severity9.8NVD Advisory· Published Dec 5, 2022· Updated May 11, 2026
CVE-2022-32224
CVE-2022-32224
Description
A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
activerecordRubyGems | >= 7.0.0, < 7.0.3.1 | 7.0.3.1 |
activerecordRubyGems | >= 6.1.0, < 6.1.6.1 | 6.1.6.1 |
activerecordRubyGems | >= 6.0.0, < 6.0.5.1 | 6.0.5.1 |
activerecordRubyGems | < 5.2.8.1 | 5.2.8.1 |
Affected products
7- cpe:2.3:a:activerecord_project:activerecord:*:*:*:*:*:ruby:*:*Range: <5.2.8.1
- Active Record/Active Recorddescription
- ghsa-coords5 versionspkg:gem/activerecordpkg:rpm/opensuse/ruby3.2-rubygem-activerecord-7.0&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-activerecord-5.2&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/rubygem-activerecord-7.0&distro=openSUSE%20Tumbleweedpkg:rpm/suse/rubygem-activerecord-5.2&distro=SUSE%20Package%20Hub%2015%20SP4
>= 7.0.0, < 7.0.3.1+ 4 more
- (no CPE)range: >= 7.0.0, < 7.0.3.1
- (no CPE)range: < 7.0.4.3-1.1
- (no CPE)range: < 5.2.3-bp154.2.3.1
- (no CPE)range: < 7.0.3.1-1.1
- (no CPE)range: < 5.2.3-bp154.2.3.1
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-3hhc-qp5v-9p2jnvdPatchThird Party AdvisoryADVISORY
- groups.google.com/g/rubyonrails-security/c/MmFO3LYQE8UnvdExploitMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-32224ghsaADVISORY
- discuss.rubyonrails.org/t/cve-2022-32224-possible-rce-escalation-bug-with-serialized-columns-in-active-record/81017ghsaWEB
- github.com/rails/rails/commit/611990f1a6c137c2d56b1ba06b27e5d2434dcd6aghsaWEB
- github.com/rails/rails/commits/main/activerecordghsaPACKAGE
- github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord/CVE-2022-32224.ymlghsaWEB
- lists.debian.org/debian-lts-announce/2026/05/msg00022.htmlnvdWEB
News mentions
0No linked articles in our index yet.