{"id":"CVE-2023-22794","aliases":["GHSA-hq7p-j377-6v63"],"url":"https://o3.security/vulnerability/CVE-2023-22794","summary":"SQL Injection Vulnerability via ActiveRecord comments","details":"A vulnerability in ActiveRecord <6.0.6.1, v6.1.7.1 and v7.0.4.1 related to the sanitization of comments. If malicious user input is passed to either the `annotate` query method, the `optimizer_hints` query method, or through the QueryLogs interface which automatically adds annotations, it may be sent to the database withinsufficient sanitization and be able to inject SQL outside of the comment.","published":"2023-02-09T00:00:00Z","modified":"2026-08-07T11:31:09.617970082Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"activerecord","fixedVersion":"6.0.6.1"},{"ecosystem":"RubyGems","name":"activerecord","fixedVersion":"6.1.7.1"},{"ecosystem":"RubyGems","name":"activerecord","fixedVersion":"7.0.4.1"}],"fix":null,"references":[{"type":"WEB","url":"https://discuss.rubyonrails.org/t/cve-2023-22794-sql-injection-vulnerability-via-activerecord-comments/82117"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/22xxx/CVE-2023-22794.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-22794"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240202-0008/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2023/dsa-5372"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:09.617970082Z"}}