CVE Vulnerabilities

CVE-2013-0276

Published: Feb 13, 2013 | Modified: Aug 08, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.

Affected Software

Name Vendor Start Version End Version
Rails Rubyonrails 3.2.0 (including) 3.2.0 (including)
Rails Rubyonrails 3.2.0-rc1 (including) 3.2.0-rc1 (including)
Rails Rubyonrails 3.2.0-rc2 (including) 3.2.0-rc2 (including)
Rails Rubyonrails 3.2.1 (including) 3.2.1 (including)
Rails Rubyonrails 3.2.2 (including) 3.2.2 (including)
Rails Rubyonrails 3.2.2-rc1 (including) 3.2.2-rc1 (including)
Rails Rubyonrails 3.2.3 (including) 3.2.3 (including)
Rails Rubyonrails 3.2.3-rc1 (including) 3.2.3-rc1 (including)
Rails Rubyonrails 3.2.3-rc2 (including) 3.2.3-rc2 (including)
Rails Rubyonrails 3.2.4 (including) 3.2.4 (including)
Rails Rubyonrails 3.2.4-rc1 (including) 3.2.4-rc1 (including)
Rails Rubyonrails 3.2.5 (including) 3.2.5 (including)
Rails Rubyonrails 3.2.6 (including) 3.2.6 (including)
Rails Rubyonrails 3.2.7 (including) 3.2.7 (including)
Rails Rubyonrails 3.2.8 (including) 3.2.8 (including)
Rails Rubyonrails 3.2.9 (including) 3.2.9 (including)
Rails Rubyonrails 3.2.10 (including) 3.2.10 (including)
Rails Rubyonrails 3.2.11 (including) 3.2.11 (including)

References