Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0276

Опубликовано: 11 фев. 2013
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=909528rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected

EPSS

Процентиль: 83%
0.0246
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

nvd
больше 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

debian
больше 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and ...

github
почти 9 лет назад

ActiveRecord vulnerable to modification of protected model attributes

EPSS

Процентиль: 83%
0.0246
Низкий

5 Medium

CVSS2