{"api_version":"1","generated_at":"2026-07-23T10:50:48+00:00","cve":"CVE-2013-0155","urls":{"html":"https://cve.report/CVE-2013-0155","api":"https://cve.report/api/cve/CVE-2013-0155.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-0155","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-0155"},"summary":{"title":"CVE-2013-0155","description":"Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain \"[nil]\" values, a related issue to CVE-2012-2660 and CVE-2012-2694.","state":"PUBLISHED","assigner":"redhat","published_at":"2013-01-13 22:55:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.html","name":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"openSUSE-SU-2013:1904-1: moderate: update for rubygem-actionpack-3_2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00081.html","name":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00081.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"openSUSE-SU-2013:1906-1: moderate: update for rubygem-actionpack-3_2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT5784","name":"http://support.apple.com/kb/HT5784","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About the security content of OS X Mountain Lion v10.8.4 and Security Update 2013-002","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00082.html","name":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00082.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"openSUSE-SU-2013:1907-1: moderate: update for rubygem-actionpack-3_2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://groups.google.com/group/rubyonrails-security/msg/bc6f13dafe130ee9?dmode=source&output=gplain","name":"https://groups.google.com/group/rubyonrails-security/msg/bc6f13dafe130ee9?dmode=source&output=gplain","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Google Groups","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A","name":"http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Wonderware Intelligence Tableau Server Ruby on Rails Improper Input Validation (Update A) | ICS-CERT","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://puppet.com/security/cve/cve-2013-0155","name":"https://puppet.com/security/cve/cve-2013-0155","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"CVE-2013-0155 | Puppet","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-0155.html","name":"http://rhn.redhat.com/errata/RHSA-2013-0155.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-0154.html","name":"http://rhn.redhat.com/errata/RHSA-2013-0154.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00003.html","name":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"openSUSE-SU-2014:0009-1: moderate: update for rubygem-actionpack-3_2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html","name":"http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"APPLE-SA-2013-06-04-1 OS X Mountain Lion v10.8.4 and Security Update\t2013-002","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2013/dsa-2609","name":"http://www.debian.org/security/2013/dsa-2609","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-2609-1 rails","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-0155","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-0155","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"155","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rubyonrails","cpe5":"rails","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"155","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rubyonrails","cpe5":"ruby_on_rails","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T14:18:09.462Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"openSUSE-SU-2013:1906","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00081.html"},{"name":"RHSA-2013:0155","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0155.html"},{"name":"DSA-2609","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2013/dsa-2609"},{"name":"openSUSE-SU-2014:0009","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00003.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://puppet.com/security/cve/cve-2013-0155"},{"name":"openSUSE-SU-2013:1907","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00082.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT5784"},{"name":"APPLE-SA-2013-06-04-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html"},{"name":"openSUSE-SU-2013:1904","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A"},{"name":"RHSA-2013:0154","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0154.html"},{"name":"[rubyonrails-security] 20130108 Unsafe Query Generation Risk in Ruby on Rails (CVE-2013-0155)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://groups.google.com/group/rubyonrails-security/msg/bc6f13dafe130ee9?dmode=source&output=gplain"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-01-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain \"[nil]\" values, a related issue to CVE-2012-2660 and CVE-2012-2694."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-12-08T10:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"openSUSE-SU-2013:1906","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00081.html"},{"name":"RHSA-2013:0155","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0155.html"},{"name":"DSA-2609","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2013/dsa-2609"},{"name":"openSUSE-SU-2014:0009","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00003.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://puppet.com/security/cve/cve-2013-0155"},{"name":"openSUSE-SU-2013:1907","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00082.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT5784"},{"name":"APPLE-SA-2013-06-04-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html"},{"name":"openSUSE-SU-2013:1904","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.html"},{"tags":["x_refsource_MISC"],"url":"http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A"},{"name":"RHSA-2013:0154","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0154.html"},{"name":"[rubyonrails-security] 20130108 Unsafe Query Generation Risk in Ruby on Rails (CVE-2013-0155)","tags":["mailing-list","x_refsource_MLIST"],"url":"https://groups.google.com/group/rubyonrails-security/msg/bc6f13dafe130ee9?dmode=source&output=gplain"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2013-0155","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain \"[nil]\" values, a related issue to CVE-2012-2660 and CVE-2012-2694."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"openSUSE-SU-2013:1906","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00081.html"},{"name":"RHSA-2013:0155","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2013-0155.html"},{"name":"DSA-2609","refsource":"DEBIAN","url":"http://www.debian.org/security/2013/dsa-2609"},{"name":"openSUSE-SU-2014:0009","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00003.html"},{"name":"https://puppet.com/security/cve/cve-2013-0155","refsource":"CONFIRM","url":"https://puppet.com/security/cve/cve-2013-0155"},{"name":"openSUSE-SU-2013:1907","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00082.html"},{"name":"http://support.apple.com/kb/HT5784","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT5784"},{"name":"APPLE-SA-2013-06-04-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html"},{"name":"openSUSE-SU-2013:1904","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.html"},{"name":"http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A","refsource":"MISC","url":"http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A"},{"name":"RHSA-2013:0154","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2013-0154.html"},{"name":"[rubyonrails-security] 20130108 Unsafe Query Generation Risk in Ruby on Rails (CVE-2013-0155)","refsource":"MLIST","url":"https://groups.google.com/group/rubyonrails-security/msg/bc6f13dafe130ee9?dmode=source&output=gplain"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2013-0155","datePublished":"2013-01-13T22:00:00.000Z","dateReserved":"2012-12-06T00:00:00.000Z","dateUpdated":"2024-08-06T14:18:09.462Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-01-13 22:55:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2.0","versionEndExcluding":"3.2.11","matchCriteriaId":"DF1D9248-14D7-4EA2-B416-D76FBA64E329"},{"vulnerable":true,"criteria":"cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.0","versionEndExcluding":"3.0.19","matchCriteriaId":"BC513BC8-F945-46A9-A63F-22585232DAE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1.0","versionEndExcluding":"3.1.10","matchCriteriaId":"08C05EBE-B0D8-48F5-8C69-5801000189BA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*","matchCriteriaId":"036E8A89-7A16-411F-9D31-676313BB7244"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"155","Ordinal":"1","Title":"CVE-2013-0155","CVE":"CVE-2013-0155","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"155","Ordinal":"1","NoteData":"Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain \"[nil]\" values, a related issue to CVE-2012-2660 and CVE-2012-2694.","Type":"Description","Title":"CVE-2013-0155"},{"CveYear":"2013","CveId":"155","Ordinal":"2","NoteData":"2013-01-13","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"155","Ordinal":"3","NoteData":"2017-12-08","Type":"Other","Title":"Modified"}]}}}