Description
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-0209 | activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls. |
Github GHSA |
GHSA-9rf5-jm6f-2fmm | Active Record subject to strong parameters protection bypass |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T10:43:06.282Z
Reserved: 2014-05-14T00:00:00.000Z
Link: CVE-2014-3514
No data.
Status : Deferred
Published: 2014-08-20T11:17:14.483
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-3514
OpenCVE Enrichment
No data.
EUVD
Github GHSA