Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rf5-jm6f-2fmm

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Active Record subject to strong parameters protection bypass

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

Пакеты

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.9

4.0.9

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

>= 4.1.0, < 4.1.5

4.1.5

EPSS

Процентиль: 56%
0.00331
Низкий

Дефекты

CWE-284

Связанные уязвимости

ubuntu
больше 11 лет назад

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

redhat
больше 11 лет назад

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

nvd
больше 11 лет назад

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

debian
больше 11 лет назад

activerecord/lib/active_record/relation/query_methods.rb in Active Rec ...

EPSS

Процентиль: 56%
0.00331
Низкий

Дефекты

CWE-284