Description
Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.
Published: 2010-10-27
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-0240 Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.
Github GHSA Github GHSA GHSA-gjxw-5w2q-7grf Rails activerecord gem has Improper Input Validation vulnerability
History

No history.

Subscriptions

Rubyonrails Rails
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T20:42:14.245Z

Reserved: 2010-10-12T00:00:00.000Z

Link: CVE-2010-3933

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-10-28T00:00:05.673

Modified: 2026-04-29T01:13:23.040

Link: CVE-2010-3933

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses