Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7577

Опубликовано: 25 янв. 2016
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.

A flaw was found in the Active Record component's handling of nested attributes in combination with the destroy flag. An attacker could possibly use this flaw to set attributes to invalid values or clear all attributes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5.2ruby193-rubygem-activerecordAffected
CloudForms Management Engine 5.3ruby193-rubygem-activerecordAffected
OpenStack Foremanruby193-rubygem-activerecordWill not fix
Red Hat Subscription Asset Managerruby193-rubygem-activerecordWill not fix
Red Hat Subscription Asset Managerrubygem-activerecordNot affected
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-actionpackFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-actionviewFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-activemodelFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-activerecordFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-activesupportFixedRHSA-2016:029624.02.2016

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1301957rubygem-activerecord: Nested attributes rejection proc bypass in Active Record

EPSS

Процентиль: 79%
0.01209
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 10 лет назад

activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.

CVSS3: 5.3
nvd
почти 10 лет назад

activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.

CVSS3: 5.3
debian
почти 10 лет назад

activerecord/lib/active_record/nested_attributes.rb in Active Record i ...

suse-cvrf
почти 10 лет назад

Security update for rubygem-activerecord-3_2

CVSS3: 5.3
github
больше 8 лет назад

Active Record Improper Access Control

EPSS

Процентиль: 79%
0.01209
Низкий

4.3 Medium

CVSS2