7.1 and 7.0 branches made any changes to active_record.rb.
I think it's more likely that change in a different file would cause CVE-2022-32224. Can you find a change that's consistent with all of the fix commits and where the vulnerable code was introduced in the repo? #7548
https://github.com/github/advisory-database/runs/73492965193