Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0276

Опубликовано: 11 фев. 2013
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CloudForms Tools 1rubygem-activemodelWill not fix
Red Hat Subscription Asset Manager 1.2candlepinFixedRHSA-2013:068626.03.2013
Red Hat Subscription Asset Manager 1.2katelloFixedRHSA-2013:068626.03.2013
Red Hat Subscription Asset Manager 1.2katello-configureFixedRHSA-2013:068626.03.2013
Red Hat Subscription Asset Manager 1.2rubygem-actionpackFixedRHSA-2013:068626.03.2013
Red Hat Subscription Asset Manager 1.2rubygem-activemodelFixedRHSA-2013:068626.03.2013
Red Hat Subscription Asset Manager 1.2rubygem-delayed_jobFixedRHSA-2013:068626.03.2013
Red Hat Subscription Asset Manager 1.2rubygem-jsonFixedRHSA-2013:068626.03.2013
Red Hat Subscription Asset Manager 1.2rubygem-nokogiriFixedRHSA-2013:068626.03.2013
Red Hat Subscription Asset Manager 1.2rubygem-rackFixedRHSA-2013:068626.03.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=909528rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected

EPSS

Процентиль: 69%
0.00606
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

nvd
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

debian
почти 13 лет назад

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and ...

github
больше 8 лет назад

ActiveRecord vulnerable to modification of protected model attributes

EPSS

Процентиль: 69%
0.00606
Низкий

5 Medium

CVSS2

Уязвимость CVE-2013-0276