CVE Vulnerabilities

CVE-2014-3514

Published: Aug 20, 2014 | Modified: Aug 08, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

Affected Software

Name Vendor Start Version End Version
Rails Rubyonrails 4.0.0 (including) 4.0.0 (including)
Rails Rubyonrails 4.0.0-beta (including) 4.0.0-beta (including)
Rails Rubyonrails 4.0.0-rc1 (including) 4.0.0-rc1 (including)
Rails Rubyonrails 4.0.0-rc2 (including) 4.0.0-rc2 (including)
Rails Rubyonrails 4.0.1 (including) 4.0.1 (including)
Rails Rubyonrails 4.0.1-rc1 (including) 4.0.1-rc1 (including)
Rails Rubyonrails 4.0.1-rc2 (including) 4.0.1-rc2 (including)
Rails Rubyonrails 4.0.1-rc3 (including) 4.0.1-rc3 (including)
Rails Rubyonrails 4.0.1-rc4 (including) 4.0.1-rc4 (including)
Rails Rubyonrails 4.0.2 (including) 4.0.2 (including)
Rails Rubyonrails 4.0.3 (including) 4.0.3 (including)
Rails Rubyonrails 4.0.4 (including) 4.0.4 (including)
Rails Rubyonrails 4.0.5 (including) 4.0.5 (including)
Rails Rubyonrails 4.0.6 (including) 4.0.6 (including)
Rails Rubyonrails 4.0.6-rc1 (including) 4.0.6-rc1 (including)
Rails Rubyonrails 4.0.6-rc2 (including) 4.0.6-rc2 (including)
Rails Rubyonrails 4.0.6-rc3 (including) 4.0.6-rc3 (including)
Rails Rubyonrails 4.0.7 (including) 4.0.7 (including)
Rails Rubyonrails 4.0.8 (including) 4.0.8 (including)
Rails Rubyonrails 4.1.0 (including) 4.1.0 (including)
Rails Rubyonrails 4.1.0-beta1 (including) 4.1.0-beta1 (including)
Rails Rubyonrails 4.1.1 (including) 4.1.1 (including)
Rails Rubyonrails 4.1.2 (including) 4.1.2 (including)
Rails Rubyonrails 4.1.2-rc1 (including) 4.1.2-rc1 (including)
Rails Rubyonrails 4.1.2-rc2 (including) 4.1.2-rc2 (including)
Rails Rubyonrails 4.1.2-rc3 (including) 4.1.2-rc3 (including)
Rails Rubyonrails 4.1.3 (including) 4.1.3 (including)
Rails Rubyonrails 4.1.4 (including) 4.1.4 (including)
Rails Ubuntu lucid *
Ruby-actionpack-2.3 Ubuntu upstream *
Ruby-activerecord-2.3 Ubuntu upstream *
Ruby-activesupport-2.3 Ubuntu upstream *
Ruby-rails-2.3 Ubuntu upstream *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 RedHat ror40-rubygem-activerecord-1:4.0.2-2.3.el6 *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS RedHat ror40-rubygem-activerecord-1:4.0.2-2.3.el6 *
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 RedHat ror40-rubygem-activerecord-1:4.0.2-2.3.el7 *

References