CVE-2013-3221
Last modified
CVE-2013-3221 is a vulnerability of currently unknown severity. The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.. EPSS estimates a 1.96% chance of exploitation in the next 30 days.
Description
The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Rubyonrails | Rails | 2.3.0 | — |
| Rubyonrails | Rails | 2.3.1 | — |
| Rubyonrails | Rails | 2.3.2 | — |
| Rubyonrails | Rails | 2.3.3 | — |
| Rubyonrails | Rails | 2.3.4 | — |
| Rubyonrails | Rails | 2.3.9 | — |
| Rubyonrails | Rails | 2.3.10 | — |
| Rubyonrails | Rails | 2.3.11 | — |
| Rubyonrails | Rails | 2.3.12 | — |
| Rubyonrails | Rails | 2.3.13 | — |
| Rubyonrails | Rails | 2.3.14 | — |
| Rubyonrails | Rails | 2.3.15 | — |
| Rubyonrails | Rails | 2.3.16 | — |
| Rubyonrails | Rails | 3.0.0 | — |
| Rubyonrails | Rails | 3.0.1 | — |
| Rubyonrails | Rails | 3.0.2 | — |
| Rubyonrails | Rails | 3.0.3 | — |
| Rubyonrails | Rails | 3.0.4 | Rc1 |
| Rubyonrails | Rails | 3.0.5 | — |
| Rubyonrails | Rails | 3.0.6 | — |
| Rubyonrails | Rails | 3.0.7 | — |
| Rubyonrails | Rails | 3.0.8 | — |
| Rubyonrails | Rails | 3.0.9 | — |
| Rubyonrails | Rails | 3.0.10 | — |
| Rubyonrails | Rails | 3.0.11 | — |
| Rubyonrails | Rails | 3.0.12 | — |
| Rubyonrails | Rails | 3.0.13 | — |
| Rubyonrails | Rails | 3.0.14 | — |
| Rubyonrails | Rails | 3.0.16 | — |
| Rubyonrails | Rails | 3.0.17 | — |
| Rubyonrails | Rails | 3.0.18 | — |
| Rubyonrails | Rails | 3.0.19 | — |
| Rubyonrails | Rails | 3.0.20 | — |
| Rubyonrails | Ruby On Rails | 3.0.4 | — |
| Rubyonrails | Rails | 3.1.0 | — |
| Rubyonrails | Rails | 3.1.1 | — |
| Rubyonrails | Rails | 3.1.2 | — |
| Rubyonrails | Rails | 3.1.3 | — |
| Rubyonrails | Rails | 3.1.4 | — |
| Rubyonrails | Rails | 3.1.5 | — |
| Rubyonrails | Rails | 3.1.6 | — |
| Rubyonrails | Rails | 3.1.7 | — |
| Rubyonrails | Rails | 3.1.8 | — |
| Rubyonrails | Rails | 3.1.9 | — |
| Rubyonrails | Rails | 3.1.10 | — |
| Rubyonrails | Rails | 3.2.0 | — |
| Rubyonrails | Rails | 3.2.1 | — |
| Rubyonrails | Rails | 3.2.2 | — |
| Rubyonrails | Rails | 3.2.3 | — |
| Rubyonrails | Rails | 3.2.4 | — |
Showing 50 of 57 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-3221?
How severe is CVE-2013-3221?
How do I fix CVE-2013-3221?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-3212vtiger CRM 5.4.0 and earlier contain local file-include vuln…8.1
- CVE-2013-3213Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 t…
- CVE-2013-3214vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vu…9.8
- CVE-2013-3215vtiger CRM 5.4.0 and earlier contain an Authentication Bypas…9.8
- CVE-2013-3219bitcoind and Bitcoin-Qt 0.8.x before 0.8.1 do not enforce a …
- CVE-2013-3220bitcoind and Bitcoin-Qt before 0.4.9rc2, 0.5.x before 0.5.8r…
- CVE-2013-3222The vcc_recvmsg function in net/atm/common.c in the Linux ke…
- CVE-2013-3223The ax25_recvmsg function in net/ax25/af_ax25.c in the Linux…
- CVE-2013-3224The bt_sock_recvmsg function in net/bluetooth/af_bluetooth.c…
- CVE-2013-3225The rfcomm_sock_recvmsg function in net/bluetooth/rfcomm/soc…
- CVE-2013-3226The sco_sock_recvmsg function in net/bluetooth/sco.c in the …
- CVE-2013-3227The caif_seqpkt_recvmsg function in net/caif/caif_socket.c i…
Are you affected by CVE-2013-3221?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
