CVE-2017-17919
Last modified
CVE-2017-17919 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input. EPSS estimates a 1.51% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rubyonrails | Ruby On Rails | <= 5.1.4 |
References
- https://kay-malwarebenchmark.github.io/blog/ruby-on-rails-arbitrary-sql-injection/Exploit, Third Party Advisory
- https://kay-malwarebenchmark.github.io/blog/ruby-on-rails-arbitrary-sql-injection/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-17919?
How severe is CVE-2017-17919?
How do I fix CVE-2017-17919?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-17912In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-…
- CVE-2017-17913In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack…
- CVE-2017-17914In ImageMagick 7.0.7-16 Q16, a vulnerability was found in th…
- CVE-2017-17915In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-…
- CVE-2017-17916SQL injection vulnerability in the 'find_by' method in Ruby …8.1
- CVE-2017-17917SQL injection vulnerability in the 'where' method in Ruby on…8.1
- CVE-2017-1792IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 throu…5.4
- CVE-2017-17920SQL injection vulnerability in the 'reorder' method in Ruby …
- CVE-2017-17924PHP Scripts Mall Professional Service Script allows remote a…
- CVE-2017-17925PHP Scripts Mall Professional Service Script has XSS via the…
- CVE-2017-17926PHP Scripts Mall Professional Service Script has a predicabl…
- CVE-2017-17927PHP Scripts Mall Professional Service Script allows remote a…
Are you affected by CVE-2017-17919?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
