CVE-2020-7981: SQL Injection
(updated )
sql.rb
in Geocoder allows Boolean-based SQL injection when within_bounding_box
is used in conjunction with untrusted sw_lat
, sw_lng
, ne_lat
, or ne_lng
data.
References
Detect and mitigate CVE-2020-7981 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →