|Release Date:||2013-01-03 (Last update can be found below the document title)|
|Description:||SQL Injection Attack in Rails Library|
|Criticality Level:||Highly Critical ( Less Critical < Critical < Moderately Critical < Highly Critical )|
|Systems Affected:||Canvas LMS|
A SQL Injection Vulnerability was discovered in the Ruby on Rails 2.3.x library that Canvas uses. No working exploit against Canvas is known, but users of Canvas CV are still encouraged to apply the patch immediately.
Fixed in Canvas Cloud. Users of Canvas CV are encouraged to either update to the most recent stable code or apply the patch manually immediately.