Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Bump activerecord from 3.2.11 to 3.2.22.3 #22

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot-preview[bot]
Copy link

Bumps activerecord from 3.2.11 to 3.2.22.3.

Dependabot compatibility score

I'll automatically resolve any conflicts with this PR as long as you don't alter it yourself.

If you'd like to skip this version, you can just close this PR. If you have any feedback just mention @dependabot in the comments below.

Bumps activerecord from 3.2.11 to 3.2.22.3.
@dependabot-preview
Copy link
Author

We've just been alerted that this update fixes a security vulnerability:

Sourced from The Ruby Advisory Database.

SQL Injection Vulnerability in Active Record
Ruby on Rails contains a flaw that may allow carrying out an SQL injection attack.
The issue is due to the PostgreSQL adapter for Active Record not properly
sanitizing user-supplied input when quoting bitstring. This may allow a remote
attacker to inject or manipulate SQL queries in the back-end database,
allowing for the manipulation or disclosure of arbitrary data.

Patched versions: ["~> 3.2.19"]
Unaffected versions: [">= 4.0.0"]

@dependabot-preview dependabot-preview bot changed the title Bump activerecord from 3.2.11 to 3.2.22.3 [Security] Bump activerecord from 3.2.11 to 3.2.22.3 Apr 6, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants