Описание
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
It was discovered that Active Record's create_with method failed to properly check attributes passed to it. A remote attacker could possibly use this flaw to bypass the strong parameter protection and modify arbitrary model attributes via mass assignment if an application using Active Record called create_with with untrusted values.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| CloudForms Management Engine 5 | cfme-gemset | Not affected | ||
| CloudForms Management Engine 5 | ruby193-rubygem-activerecord | Not affected | ||
| OpenShift Enterprise 1 | ruby193-rubygem-activerecord | Not affected | ||
| OpenStack Foreman | ruby193-rubygem-activerecord | Not affected | ||
| Red Hat OpenStack Platform 4 | ruby193-rubygem-activerecord | Not affected | ||
| Red Hat Software Collections | ruby193-rubygem-activerecord | Not affected | ||
| Red Hat Subscription Asset Manager | ruby193-rubygem-activerecord | Not affected | ||
| Red Hat Subscription Asset Manager | rubygem-activerecord | Not affected | ||
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 | ror40-rubygem-activerecord | Fixed | RHSA-2014:1102 | 27.08.2014 |
| Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS | ror40-rubygem-activerecord | Fixed | RHSA-2014:1102 | 27.08.2014 |
Показывать по
Дополнительная информация
Статус:
5.8 Medium
CVSS2
Связанные уязвимости
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
activerecord/lib/active_record/relation/query_methods.rb in Active Rec ...
Active Record subject to strong parameters protection bypass
5.8 Medium
CVSS2