Candidate: CVE-2020-7981 PublicDate: 2020-01-25 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7981 https://github.com/alexreisner/geocoder/commit/dcdc3d8675411edce3965941a2ca7c441ca48613 https://github.com/alexreisner/geocoder/compare/v1.6.0...v1.6.1 Description: sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=949870 Priority: untriaged Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_ruby-geocoder: upstream_ruby-geocoder: needs-triage precise/esm_ruby-geocoder: DNE trusty_ruby-geocoder: ignored (out of standard support) trusty/esm_ruby-geocoder: DNE xenial_ruby-geocoder: DNE bionic_ruby-geocoder: DNE eoan_ruby-geocoder: ignored (reached end-of-life) focal_ruby-geocoder: not-affected (1.5.1-3) devel_ruby-geocoder: not-affected (1.5.1-3)