activerecord vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the activerecord package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • H
Denial of Service (DoS)

<6.1.7.1>=7.0.0, <7.0.4.1
  • H
SQL Injection

>=6.0.0, <6.0.6.1>=6.1.0, <6.1.7.1>=7.0.0, <7.0.4.1
  • C
Remote Code Execution (RCE)

<5.2.8.1>=6.0.0, <6.0.5.1>=6.1.0, <6.1.6.1>=7.0.0, <7.0.3.1
  • H
Data Injection

>=2.3.2, <4.0.0.beta1
  • H
Regular Expression Denial of Service (ReDoS)

>=6.1.0, <6.1.2.1>=6.0.0, <6.0.3.5>=4.2.0, <5.2.4.5
  • H
SQL Injection

>=2.0.0, <2.3.13>=3.0.0, <3.0.10>=3.1.0.beta1, <3.1.0.rc6
  • H
SQL Injection

>=3.0.0, <=3.0.3
  • H
Unsafe Query Generation

>=4.2.0, <4.2.7.1
  • M
Nested Attributes Rejection Bypass

>=4.3, <5.0.0.beta1.1>=4.2, <4.2.5.1>=3.2.23, <4.1.14.1>=3.1, <3.2.22.1
  • H
Arbitrary Data Injection

>=4.1, <4.1.5>=4.0.0, <4.0.9
  • H
SQL Injection

>=4.1.0, <4.1.3>=4.0.0, <4.0.7
  • H
SQL Injection

>=3.3, <4.0.0<3.2.19
  • M
Data Injection

>=4.1.0.beta1, <4.1.0.beta2>=3.2.0, <4.0.3
  • M
Denial of Service (DoS)

>=3.2, <3.2.13>=3.1, <3.1.12>=2.4, <3.0.0<2.3.18
  • C
Remote Code Execution

>=2.4, <3.1.0<2.3.17
  • M
Access Restriction Bypass

>=3.2, <3.2.12>=2.4, <3.1.11<2.3.17
  • M
JSON Parameter Parsing Query Bypass

>=3.2, <3.2.11>=3.1, <3.1.10>=2.4, <3.0.19<2.3.16
  • H
SQL Injection

>=3.2, <3.2.10>=3.1, <3.1.9<3.0.18
  • M
SQL Injection

>=3.2, <3.2.4>=3.1, <3.1.5>=2.4, <3.0.13<2.3.14
  • M
Unsafe Query Generation

>=3.2, <3.2.4>=3.1, <3.1.5<3.0.13