Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Fix for SQL injection on :limit and :offset should be backported

#964

The fix in #288 is a serious security vulnerability and should be backported to all stable branches.

Reported by Jon Leighton · September 3rd, 2008 @ 03:51 PM

State: resolved
Milestone: 2.0.3
Assigned to: Jeremy Kemper Jeremy Kemper
Importance: none

Activity

  1. August Lilleaas
  2. Smeevil
  3. Jon Leighton
    Jon Leighton

    More info about the problem on this blog post: http://blog.innerewut.de/2008/6/...

    The facts we have:

    • The problem is fixed in the abstract adapter for 2.1.0
    • The problem is not fixed for the 2.0 or 1.2 branches
    • The problem is not fixed for the mysql adapter for 2.1.0, but will be fixed when 2.1.1 is released. This is not such a huge issue as mysql stops more than one query being sent at once

    So basically it's not a huge issue that the mysql adapter fix hasn't been released for the 2.1 branch, but no fix at all has been released for the other branches and so they are both vulnerable.

    September 3rd, 2008 @ 04:08 PM

  4. Jeremy Kemper
    Jeremy Kemper
    • State changed from new to open
    • Assigned user set to Jeremy Kemper
    • Milestone changed from 2.x to 2.0.3

    We surveyed folks a while back. Pretty much nobody is affected by this. I agree it's backport-worthy, but it's not a crisis.

    Care to backport it?

    September 3rd, 2008 @ 10:22 PM

  5. Jon Leighton
    Jon Leighton

    What's the criteria for a security issue being considered a "priority"? I run with postgres on the 2.0 branch, which means my application would be vulnerable if we were using user-specified offset/limit. Granted a very small number of people run postgres/sqlite compared to mysql, and presumably a smaller number still allow the user to specify limit/offset, but it seems this could affect somebody, and would be quite serious for them if they were targeted.

    Anyway, I'd be happy to backport it, will report back with a patch.

    September 4th, 2008 @ 07:41 AM

  6. Jon Leighton
  7. Frederick Cheung
    Frederick Cheung
    • Tag changed from 2.0-stable, activerecord, bug to 2.0-stable, activerecord, bug, patch, tested
    • State changed from open to resolved

    This was part of 2.0.5 commit

    December 12th, 2008 @ 02:01 PM