activerecord vulnerabilities

Databases on Rails. Build a persistent domain model by mapping database tables to Ruby classes. Strong conventions for associations, validations, aggregations, migrations, and testing come baked-in.

Direct Vulnerabilities

Known vulnerabilities in the activerecord package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Remote Code Execution (RCE)

<5.2.8.1 >=6.0.0, <6.0.5.1 >=6.1.0, <6.1.6.1 >=7.0.0, <7.0.3.1
  • H
Data Injection

>=2.3.2, <4.0.0.beta1
  • H
Regular Expression Denial of Service (ReDoS)

>=6.1.0, <6.1.2.1 >=6.0.0, <6.0.3.5 >=4.2.0, <5.2.4.5
  • H
SQL Injection

>=2.0.0, <2.3.13 >=3.0.0, <3.0.10 >=3.1.0.beta1, <3.1.0.rc6
  • H
SQL Injection

>=3.0.0, <=3.0.3
  • H
Unsafe Query Generation

>=4.2.0, <4.2.7.1
  • M
Nested Attributes Rejection Bypass

>=4.3, <5.0.0.beta1.1 >=4.2, <4.2.5.1 >=3.2.23, <4.1.14.1 >=3.1, <3.2.22.1
  • H
Arbitrary Data Injection

>=4.1, <4.1.5 >=4.0.0, <4.0.9
  • H
SQL Injection

>=4.1.0, <4.1.3 >=4.0.0, <4.0.7
  • H
SQL Injection

>=3.3, <4.0.0 <3.2.19
  • M
Data Injection

>=4.1.0.beta1, <4.1.0.beta2 >=3.2.0, <4.0.3
  • M
Denial of Service (DoS)

>=3.2, <3.2.13 >=3.1, <3.1.12 >=2.4, <3.0.0 <2.3.18
  • C
Remote Code Execution

>=2.4, <3.1.0 <2.3.17
  • M
Access Restriction Bypass

>=3.2, <3.2.12 >=2.4, <3.1.11 <2.3.17
  • M
JSON Parameter Parsing Query Bypass

>=3.2, <3.2.11 >=3.1, <3.1.10 >=2.4, <3.0.19 <2.3.16
  • H
SQL Injection

>=3.2, <3.2.10 >=3.1, <3.1.9 <3.0.18
  • M
Unsafe Query Generation

>=3.2, <3.2.4 >=3.1, <3.1.5 <3.0.13
  • M
SQL Injection

>=3.2, <3.2.4 >=3.1, <3.1.5 >=2.4, <3.0.13 <2.3.14