ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rails | Rubyonrails | 3.2.0 (including) | 3.2.0 (including) |
Rails | Rubyonrails | 3.2.0-rc1 (including) | 3.2.0-rc1 (including) |
Rails | Rubyonrails | 3.2.0-rc2 (including) | 3.2.0-rc2 (including) |
Rails | Rubyonrails | 3.2.1 (including) | 3.2.1 (including) |
Rails | Rubyonrails | 3.2.2 (including) | 3.2.2 (including) |
Rails | Rubyonrails | 3.2.2-rc1 (including) | 3.2.2-rc1 (including) |
Rails | Rubyonrails | 3.2.3 (including) | 3.2.3 (including) |
Rails | Rubyonrails | 3.2.3-rc1 (including) | 3.2.3-rc1 (including) |
Rails | Rubyonrails | 3.2.3-rc2 (including) | 3.2.3-rc2 (including) |
Rails | Rubyonrails | 3.2.4 (including) | 3.2.4 (including) |
Rails | Rubyonrails | 3.2.4-rc1 (including) | 3.2.4-rc1 (including) |
Rails | Rubyonrails | 3.2.5 (including) | 3.2.5 (including) |
Rails | Rubyonrails | 3.2.6 (including) | 3.2.6 (including) |
Rails | Rubyonrails | 3.2.7 (including) | 3.2.7 (including) |
Rails | Rubyonrails | 3.2.8 (including) | 3.2.8 (including) |
Rails | Rubyonrails | 3.2.9 (including) | 3.2.9 (including) |
Rails | Rubyonrails | 3.2.10 (including) | 3.2.10 (including) |
Rails | Rubyonrails | 3.2.11 (including) | 3.2.11 (including) |