update_by_case before 0.1.3 can be vulnerable to sql injection
Moderate severity
GitHub Reviewed
Published
Aug 10, 2022
in
camilova/activerecord-update-by-case
•
Updated Jan 27, 2023
Description
Published to the GitHub Advisory Database
Aug 11, 2022
Reviewed
Aug 11, 2022
Published by the National Vulnerability Database
Aug 12, 2022
Last updated
Jan 27, 2023
Before version 0.1.3
update_by_case
gem used custom sql strings, and it was not sanitized, making it vulnerable to sql injection. Upgrade to version >= 0.1.3 that usesArel
instead to construct the resulting sql statement, with sanitized sql.References