SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:06:49.394Z
Reserved: 2017-12-26T00:00:00
Link: CVE-2017-17919
Updated: 2024-08-05T21:06:49.394Z
Status : Deferred
Published: 2017-12-29T16:29:00.297
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-17919
No data.
OpenCVE Enrichment
No data.
Weaknesses