Skip to content

[GHSA-h6w6-xmqv-7q78] activerecord vulnerable to SQL Injection#6376

Merged
advisory-database[bot] merged 1 commit intotjuyuxinzhang/advisory-improvement-6376from
tjuyuxinzhang-GHSA-h6w6-xmqv-7q78
Nov 3, 2025
Merged

[GHSA-h6w6-xmqv-7q78] activerecord vulnerable to SQL Injection#6376
advisory-database[bot] merged 1 commit intotjuyuxinzhang/advisory-improvement-6376from
tjuyuxinzhang-GHSA-h6w6-xmqv-7q78

Conversation

@tjuyuxinzhang
Copy link

Updates

  • Affected products

Comments
The current GitHub advisory omits the affected 3.1.x release branch range (>=3.1.0.beta1, <3.1.0.rc5), even though this information is explicitly confirmed by:
The Rails Security Advisory http://groups.google.com/group/rubyonrails-security/msg/b1a85d36b0f9dd30
The official patch commit rails/rails@8a39f41
Debian DSA-2301 and Red Hat Bugzilla #731438
This correction ensures full coverage of all affected release lines and clarifies that 3.1.0.rc5 is the non-vulnerable version.

@github-actions github-actions bot changed the base branch from main to tjuyuxinzhang/advisory-improvement-6376 November 1, 2025 19:17
@advisory-database advisory-database bot merged commit 84026f2 into tjuyuxinzhang/advisory-improvement-6376 Nov 3, 2025
4 checks passed
@advisory-database
Copy link
Contributor

Hi @tjuyuxinzhang! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the tjuyuxinzhang-GHSA-h6w6-xmqv-7q78 branch November 3, 2025 13:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant