Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-3514

Опубликовано: 20 авг. 2014
Источник: debian

Описание

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2:4.1.5-1package
railsnot-affectedwheezypackage
railsend-of-lifesqueezepackage
rails-3.2not-affectedpackage
ruby-activerecord-2.3not-affectedpackage
ruby-activerecord-3.2not-affectedpackage

Связанные уязвимости

ubuntu
больше 11 лет назад

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

redhat
больше 11 лет назад

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

nvd
больше 11 лет назад

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

github
больше 8 лет назад

Active Record subject to strong parameters protection bypass