Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlyZjUtam02Zi0yZm1t
Active Record subject to strong parameters protection bypass
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
Permalink: https://github.com/advisories/GHSA-9rf5-jm6f-2fmmJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlyZjUtam02Zi0yZm1t
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 5 years ago
Updated: 3 months ago
Identifiers: GHSA-9rf5-jm6f-2fmm, CVE-2014-3514
References:
- https://nvd.nist.gov/vuln/detail/CVE-2014-3514
- http://openwall.com/lists/oss-security/2014/08/18/10
- http://rhn.redhat.com/errata/RHSA-2014-1102.html
- https://github.com/advisories/GHSA-9rf5-jm6f-2fmm
Affected Packages
rubygems:activerecord
Versions: >= 4.1.0, < 4.1.5, >= 4.0.0, < 4.0.9Fixed in: 4.1.5, 4.0.9