Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7577

Опубликовано: 25 янв. 2016
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.

A flaw was found in the Active Record component's handling of nested attributes in combination with the destroy flag. An attacker could possibly use this flaw to set attributes to invalid values or clear all attributes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5ruby193-rubygem-activerecordAffected
OpenStack Foremanruby193-rubygem-activerecordWill not fix
Red Hat Subscription Asset Managerruby193-rubygem-activerecordWill not fix
Red Hat Subscription Asset Managerrubygem-activerecordNot affected
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-actionpackFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-actionviewFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-activemodelFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-activerecordFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-activesupportFixedRHSA-2016:029624.02.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6ror40-rubygem-actionpackFixedRHSA-2016:045415.03.2016

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1301957rubygem-activerecord: Nested attributes rejection proc bypass in Active Record

EPSS

Процентиль: 90%
0.0425
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 10 лет назад

activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.

CVSS3: 5.3
nvd
больше 10 лет назад

activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.

CVSS3: 5.3
debian
больше 10 лет назад

activerecord/lib/active_record/nested_attributes.rb in Active Record i ...

suse-cvrf
больше 10 лет назад

Security update for rubygem-activerecord-3_2

CVSS3: 5.3
github
почти 9 лет назад

Active Record Improper Access Control

EPSS

Процентиль: 90%
0.0425
Низкий

4.3 Medium

CVSS2