This advisory concerns a security risk in all supported versions of Active Record. There is no patch to apply for this issue.
Due to the query API that Active Record supports, there is a risk of unsafe query generation in two scenarios. Databases with a table that contains a column with the same name as the table and queries with join aliases which conflict with column names could be vulnerable to an attack where the attacker can perform certain manipulations to the SQL queries generated by Rails.
A vulnerable application will either contain columns named identically to their table, or have column names which conflict with join aliases.
For example, if you had a model called SecurityToken, which contained an attribute called
security_tokens then the following code could be manipulated to return additional records: