Количество 9
Количество 9
CVE-2015-7577
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.
CVE-2015-7577
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.
CVE-2015-7577
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.
CVE-2015-7577
activerecord/lib/active_record/nested_attributes.rb in Active Record i ...
SUSE-SU-2016:0619-1
Security update for rubygem-activerecord-3_2
GHSA-xrr6-3pc4-m447
Active Record Improper Access Control
BDU:2016-00814
Уязвимость программной платформы Ruby on Rails, позволяющая нарушителю обойти существующие политики ограничения доступа
openSUSE-SU-2016:0372-1
Security update for rubygem-actionpack-4_2, rubygem-actionview-4_2, rubygem-activemodel-4_2, rubygem-activerecord-4_2, rubygem-activesupport-4_2
SUSE-SU-2016:1146-1
Security update for portus
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2015-7577 activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature. | CVSS3: 5.3 | 1% Низкий | почти 10 лет назад | |
CVE-2015-7577 activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature. | CVSS2: 4.3 | 1% Низкий | около 10 лет назад | |
CVE-2015-7577 activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature. | CVSS3: 5.3 | 1% Низкий | почти 10 лет назад | |
CVE-2015-7577 activerecord/lib/active_record/nested_attributes.rb in Active Record i ... | CVSS3: 5.3 | 1% Низкий | почти 10 лет назад | |
SUSE-SU-2016:0619-1 Security update for rubygem-activerecord-3_2 | 1% Низкий | почти 10 лет назад | ||
GHSA-xrr6-3pc4-m447 Active Record Improper Access Control | CVSS3: 5.3 | 1% Низкий | больше 8 лет назад | |
BDU:2016-00814 Уязвимость программной платформы Ruby on Rails, позволяющая нарушителю обойти существующие политики ограничения доступа | CVSS2: 5 | 1% Низкий | почти 10 лет назад | |
openSUSE-SU-2016:0372-1 Security update for rubygem-actionpack-4_2, rubygem-actionview-4_2, rubygem-activemodel-4_2, rubygem-activerecord-4_2, rubygem-activesupport-4_2 | около 10 лет назад | |||
SUSE-SU-2016:1146-1 Security update for portus | почти 10 лет назад |
Уязвимостей на страницу