A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 64bit signed integer is provided to the PostgreSQL connection adapter, it will treat the target column type as numeric. Comparing integer values against numeric values can result in a slow sequential scan resulting in potential Denial of Service.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0336 | Denial of Service Vulnerability in ActiveRecord's PostgreSQL adapter |
Github GHSA |
GHSA-579w-22j4-4749 | Denial of Service Vulnerability in ActiveRecord's PostgreSQL adapter |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-03-25T13:43:54.894Z
Reserved: 2022-11-01T00:00:00.000Z
Link: CVE-2022-44566
Updated: 2024-08-03T13:54:03.838Z
Status : Modified
Published: 2023-02-09T20:15:11.017
Modified: 2025-03-25T14:15:18.393
Link: CVE-2022-44566
OpenCVE Enrichment
No data.
EUVD
Github GHSA