Bugzilla – Bug 1074348
VUL-0: CVE-2017-17919: rubygem-rails: SQL injection vulnerability in the 'order' method
Last modified: 2018-02-20 23:36:53 UTC
CVE-2017-17919 SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-17919 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17919 http://www.cvedetails.com/cve/CVE-2017-17919/
Talked to upstream. The issue is Not Applicable. Closing as invalid.