CVE-2017-17920
Last modified
CVE-2017-17920 is a vulnerability of currently unknown severity. SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input. EPSS estimates a 1.51% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rubyonrails | Ruby On Rails | <= 5.1.4 |
References
- https://kay-malwarebenchmark.github.io/blog/ruby-on-rails-arbitrary-sql-injection/Exploit, Third Party Advisory
- https://kay-malwarebenchmark.github.io/blog/ruby-on-rails-arbitrary-sql-injection/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-17920?
How severe is CVE-2017-17920?
How do I fix CVE-2017-17920?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-17914In ImageMagick 7.0.7-16 Q16, a vulnerability was found in th…
- CVE-2017-17915In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-…
- CVE-2017-17916SQL injection vulnerability in the 'find_by' method in Ruby …8.1
- CVE-2017-17917SQL injection vulnerability in the 'where' method in Ruby on…8.1
- CVE-2017-17919SQL injection vulnerability in the 'order' method in Ruby on…8.1
- CVE-2017-1792IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 throu…5.4
- CVE-2017-17924PHP Scripts Mall Professional Service Script allows remote a…
- CVE-2017-17925PHP Scripts Mall Professional Service Script has XSS via the…
- CVE-2017-17926PHP Scripts Mall Professional Service Script has a predicabl…
- CVE-2017-17927PHP Scripts Mall Professional Service Script allows remote a…
- CVE-2017-17928PHP Scripts Mall Professional Service Script has SQL injecti…
- CVE-2017-17929PHP Scripts Mall Professional Service Script has XSS via the…
Are you affected by CVE-2017-17920?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
