The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS attack. This only impacts Rails applications that are using PostgreSQL along with money type columns that take user input.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade rails | Jun 11, 2021 | Feb 11, 2021 |
| Freebsd | — | Upgrade rubygem-actionpack61Upgrade rubygem-actionpack60Upgrade rubygem-activerecord61Upgrade rubygem-activerecord52Upgrade rubygem-activerecord60 | Feb 18, 2021 | Feb 17, 2021 |
| Ruby_on_rails | — | Upgrade to the latest version of Ruby on Rails | Feb 19, 2021 | Feb 11, 2021 |
| Suse | — | Upgrade ruby2.5-rubygem-activerecord-5_1 | Nov 10, 2021 | Feb 11, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub