PT-2014-5367 · Ruby · Ruby On Rails

Published

2014-08-20

·

Updated

2024-06-15

·

CVE-2014-3514

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ruby on Rails versions 4.0.x through 4.0.8 Ruby on Rails versions 4.1.x through 4.1.4
Description The issue allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create with calls. This is related to the activerecord/lib/active record/relation/query methods.rb file in Active Record.
Recommendations For Ruby on Rails versions 4.0.x through 4.0.8, update to version 4.0.9 or later. For Ruby on Rails versions 4.1.x through 4.1.4, update to version 4.1.5 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3514
GHSA-9RF5-JM6F-2FMM
GHSA-HM48-76WH-Q86V
OPENSUSE-SU-2024:10207-1
RHSA-2014:1102

Affected Products

Ruby On Rails