GHSA-hrj5-qp7x-rpg6
Dashboard / Vulnerabilities / GHSA-hrj5-qp7x-rpg6
Summary: SQL Injection in marginalia
Details: marginalia < 1.6 is affected by SQL Injection. The impact is an injection of any SQL queries when a user controller argument is added as a component. This issue affects users that add a component that is user controller, for instance a parameter or a header. The attack vector is inputting of SQL to a vulnerable vector (header, http parameter, etc). The fixed version is 1.6.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-1010191, https://github.com/basecamp/marginalia/pull/73, https://github.com/basecamp/marginalia, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/marginalia/CVE-2019-1010191.yml
Affected packages
Package
Name: marginalia
Purl: pkg:gem/marginalia
Affected ranges
Type: ECOSYSTEM
Events:
