CVE-2012-6496: Ruby on Rails find_by_* Methods Authlogic SQL Injection Bypass
(updated )
Due to the way dynamic finders in Active Record extract options from method parameters, a method parameter can mistakenly be used as a scope. Carefully crafted requests can use the scope to inject arbitrary SQL.
References
Detect and mitigate CVE-2012-6496 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →