Providing security resources for the Ruby community.
Follow us @rubysec or email us via info at

Advisory Archive


gem: mysql-binuuid-rails
date: 2018-10-19
cve: 2018-18476
title: mysql-binuuid-rails allows SQL Injection by removing default string escaping
description: |
  mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes
  default string escaping for affected database columns. ActiveRecord does not
  explicitly escape the Binary data type (Type::Binary::Data) for mysql.
  mysql-binuuid-rails uses a data type that is derived from the base Binary
  type, except, it doesn’t convert the value to hex. Instead, it assumes the
  string value provided is a valid hex string and doesn’t do any checks on it.
- ">= 1.1.1"
  url: '[""]'