CVE Vulnerabilities

CVE-2014-3514

Published: Aug 20, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

Affected Software

NameVendorStart VersionEnd Version
RailsRubyonrails4.0.0 (including)4.0.0 (including)
RailsRubyonrails4.0.0-beta (including)4.0.0-beta (including)
RailsRubyonrails4.0.0-rc1 (including)4.0.0-rc1 (including)
RailsRubyonrails4.0.0-rc2 (including)4.0.0-rc2 (including)
RailsRubyonrails4.0.1 (including)4.0.1 (including)
RailsRubyonrails4.0.1-rc1 (including)4.0.1-rc1 (including)
RailsRubyonrails4.0.1-rc2 (including)4.0.1-rc2 (including)
RailsRubyonrails4.0.1-rc3 (including)4.0.1-rc3 (including)
RailsRubyonrails4.0.1-rc4 (including)4.0.1-rc4 (including)
RailsRubyonrails4.0.2 (including)4.0.2 (including)
RailsRubyonrails4.0.3 (including)4.0.3 (including)
RailsRubyonrails4.0.4 (including)4.0.4 (including)
RailsRubyonrails4.0.5 (including)4.0.5 (including)
RailsRubyonrails4.0.6 (including)4.0.6 (including)
RailsRubyonrails4.0.6-rc1 (including)4.0.6-rc1 (including)
RailsRubyonrails4.0.6-rc2 (including)4.0.6-rc2 (including)
RailsRubyonrails4.0.6-rc3 (including)4.0.6-rc3 (including)
RailsRubyonrails4.0.7 (including)4.0.7 (including)
RailsRubyonrails4.0.8 (including)4.0.8 (including)
RailsRubyonrails4.1.0 (including)4.1.0 (including)
RailsRubyonrails4.1.0-beta1 (including)4.1.0-beta1 (including)
RailsRubyonrails4.1.1 (including)4.1.1 (including)
RailsRubyonrails4.1.2 (including)4.1.2 (including)
RailsRubyonrails4.1.2-rc1 (including)4.1.2-rc1 (including)
RailsRubyonrails4.1.2-rc2 (including)4.1.2-rc2 (including)
RailsRubyonrails4.1.2-rc3 (including)4.1.2-rc3 (including)
RailsRubyonrails4.1.3 (including)4.1.3 (including)
RailsRubyonrails4.1.4 (including)4.1.4 (including)
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6RedHatror40-rubygem-activerecord-1:4.0.2-2.3.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSRedHatror40-rubygem-activerecord-1:4.0.2-2.3.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7RedHatror40-rubygem-activerecord-1:4.0.2-2.3.el7*
RailsUbuntulucid*
Ruby-actionpack-2.3Ubuntuupstream*
Ruby-activerecord-2.3Ubuntuupstream*
Ruby-activesupport-2.3Ubuntuupstream*
Ruby-rails-2.3Ubuntuupstream*

References