Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gr44-7grc-37vq

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

ActiveRecord vulnerable to modification of protected model attributes

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

Пакеты

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

< 2.3.17

2.3.17

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

>= 3.1.0, < 3.1.11

3.1.11

Наименование

activerecord

rubygems
Затронутые версииВерсия исправления

>= 3.2.0, < 3.2.12

3.2.12

EPSS

Процентиль: 69%
0.00606
Низкий

Дефекты

CWE-284

Связанные уязвимости

ubuntu
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

redhat
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

nvd
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

debian
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and ...

EPSS

Процентиль: 69%
0.00606
Низкий

Дефекты

CWE-284