activerecord vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the activerecord package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Improper Neutralization

<7.1.5.2>=7.2, <7.2.2.2>=8.0, <8.0.2.1
  • H
Denial of Service (DoS)

<6.1.7.1>=7.0.0, <7.0.4.1
  • H
SQL Injection

>=6.0.0, <6.0.6.1>=6.1.0, <6.1.7.1>=7.0.0, <7.0.4.1
  • C
Remote Code Execution (RCE)

<5.2.8.1>=6.0.0, <6.0.5.1>=6.1.0, <6.1.6.1>=7.0.0, <7.0.3.1
  • H
Data Injection

>=2.3.2, <4.0.0.beta1
  • H
Regular Expression Denial of Service (ReDoS)

>=6.1.0, <6.1.2.1>=6.0.0, <6.0.3.5>=4.2.0, <5.2.4.5
  • H
SQL Injection

>=2.0.0, <2.3.13>=3.0.0, <3.0.10>=3.1.0.beta1, <3.1.0.rc6
  • H
SQL Injection

>=3.0.0, <=3.0.3
  • H
Unsafe Query Generation

>=4.2.0, <4.2.7.1
  • M
Nested Attributes Rejection Bypass

>=4.3, <5.0.0.beta1.1>=4.2, <4.2.5.1>=3.2.23, <4.1.14.1>=3.1, <3.2.22.1
  • H
Arbitrary Data Injection

>=4.1, <4.1.5>=4.0.0, <4.0.9
  • H
SQL Injection

>=4.1.0, <4.1.3>=4.0.0, <4.0.7
  • H
SQL Injection

>=3.3, <4.0.0<3.2.19
  • M
Data Injection

>=4.1.0.beta1, <4.1.0.beta2>=3.2.0, <4.0.3
  • M
Denial of Service (DoS)

>=3.2, <3.2.13>=3.1, <3.1.12>=2.4, <3.0.0<2.3.18
  • M
Access Restriction Bypass

>=3.2, <3.2.12>=2.4, <3.1.11<2.3.17
  • C
Remote Code Execution (RCE)

<2.3.17>=2.4, <3.1.0
  • M
JSON Parameter Parsing Query Bypass

>=3.2, <3.2.11>=3.1, <3.1.10>=2.4, <3.0.19<2.3.16
  • H
SQL Injection

>=3.2, <3.2.10>=3.1, <3.1.9<3.0.18
  • M
SQL Injection

>=3.2, <3.2.4>=3.1, <3.1.5>=2.4, <3.0.13<2.3.14
  • M
Unsafe Query Generation

>=3.2, <3.2.4>=3.1, <3.1.5<3.0.13