CVE Vulnerabilities

CVE-2016-0753

Published: Feb 16, 2016 | Modified: May 19, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.

Affected Software

Name Vendor Start Version End Version
Rails Rubyonrails 4.1.0 (including) 4.1.14.1 (excluding)
Rails Rubyonrails 4.2.0 (including) 4.2.5.1 (excluding)
Rails Rubyonrails 5.0.0-beta1 (including) 5.0.0-beta1 (including)
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-ror41-rubygem-actionpack-1:4.1.5-3.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-ror41-rubygem-actionview-0:4.1.5-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-ror41-rubygem-activemodel-0:4.1.5-2.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-ror41-rubygem-activerecord-1:4.1.5-2.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-ror41-rubygem-activesupport-1:4.1.5-3.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat rh-ror41-rubygem-actionpack-1:4.1.5-3.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat rh-ror41-rubygem-actionview-0:4.1.5-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat rh-ror41-rubygem-activemodel-0:4.1.5-2.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat rh-ror41-rubygem-activerecord-1:4.1.5-2.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat rh-ror41-rubygem-activesupport-1:4.1.5-3.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat rh-ror41-rubygem-actionpack-1:4.1.5-3.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat rh-ror41-rubygem-actionview-0:4.1.5-4.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat rh-ror41-rubygem-activemodel-0:4.1.5-2.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat rh-ror41-rubygem-activerecord-1:4.1.5-2.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS RedHat rh-ror41-rubygem-activesupport-1:4.1.5-3.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-ror41-rubygem-actionpack-1:4.1.5-3.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-ror41-rubygem-actionview-0:4.1.5-4.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-ror41-rubygem-activemodel-0:4.1.5-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-ror41-rubygem-activerecord-1:4.1.5-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-ror41-rubygem-activesupport-1:4.1.5-3.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat rh-ror41-rubygem-actionpack-1:4.1.5-3.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat rh-ror41-rubygem-actionview-0:4.1.5-4.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat rh-ror41-rubygem-activemodel-0:4.1.5-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat rh-ror41-rubygem-activerecord-1:4.1.5-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat rh-ror41-rubygem-activesupport-1:4.1.5-3.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat rh-ror41-rubygem-actionpack-1:4.1.5-3.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat rh-ror41-rubygem-actionview-0:4.1.5-4.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat rh-ror41-rubygem-activemodel-0:4.1.5-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat rh-ror41-rubygem-activerecord-1:4.1.5-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS RedHat rh-ror41-rubygem-activesupport-1:4.1.5-3.el7 *
Rails Ubuntu artful *
Rails Ubuntu upstream *
Rails Ubuntu vivid *
Rails Ubuntu wily *
Rails Ubuntu yakkety *
Rails Ubuntu zesty *
Ruby-actionpack-2.3 Ubuntu upstream *
Ruby-activerecord-2.3 Ubuntu upstream *
Ruby-activesupport-2.3 Ubuntu upstream *
Ruby-rails-2.3 Ubuntu upstream *

References