PT-2014-5367 · Ruby · Ruby On Rails

Publicado

2014-08-20

·

Atualizado

2024-06-15

·

CVE-2014-3514

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ruby on Rails versions 4.0.x through 4.0.8 Ruby on Rails versions 4.1.x through 4.1.4
Description The issue allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create with calls. This is related to the activerecord/lib/active record/relation/query methods.rb file in Active Record.
Recommendations For Ruby on Rails versions 4.0.x through 4.0.8, update to version 4.0.9 or later. For Ruby on Rails versions 4.1.x through 4.1.4, update to version 4.1.5 or later.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3514
GHSA-9RF5-JM6F-2FMM
GHSA-HM48-76WH-Q86V
OPENSUSE-SU-2024:10207-1
RHSA-2014:1102

Produtos afetados

Ruby On Rails