{"id":"GHSA-rx7j-mw4c-76g9","summary":"Authlogic Information Exposure vulnerability","details":"The Authlogic gem for Ruby on Rails prior to version 3.3.0 makes potentially unsafe `find_by_id` method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in `secret_token.rb` in an open-source product.","aliases":["CVE-2012-6497"],"modified":"2024-12-05T05:45:32.207280Z","published":"2022-05-14T00:54:20Z","database_specific":{"github_reviewed_at":"2023-01-26T23:55:17Z","nvd_published_at":"2013-01-04T04:46:00Z","cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-6497"},{"type":"WEB","url":"https://github.com/binarylogic/authlogic/pull/341"},{"type":"WEB","url":"https://github.com/binarylogic/authlogic/commit/1d57a6c4abe43a3c0b4ef578486ea00e1f7a9873"},{"type":"PACKAGE","url":"https://github.com/binarylogic/authlogic"},{"type":"WEB","url":"https://web.archive.org/web/20130104161608/http://www.securityfocus.com/bid/57084"},{"type":"WEB","url":"https://web.archive.org/web/20130116043311/http://phenoelit.org/blog/archives/2012/12/21/let_me_github_that_for_you/index.html"},{"type":"WEB","url":"http://blog.phusion.nl/2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-facts"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2013/01/03/12"}],"affected":[{"package":{"name":"authlogic","ecosystem":"RubyGems","purl":"pkg:gem/authlogic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.0"}]}],"versions":["0.10.4","1.0.0","1.1.0","1.1.1","1.1.2","1.2.0","1.2.1","1.2.2","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.3.8","1.3.9","1.4.0","1.4.1","1.4.2","1.4.3","2.0.0","2.0.1","2.0.11","2.0.12","2.0.13","2.0.14","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.1.0","2.1.1","2.1.10","2.1.11","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","3.0.0","3.0.1","3.0.2","3.0.3","3.1.0","3.1.1","3.1.2","3.1.3","3.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rx7j-mw4c-76g9/GHSA-rx7j-mw4c-76g9.json"}}],"schema_version":"1.9.0"}