7.5

CVE-2014-3514

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RubyonrailsRails Version4.0.0 Update-
RubyonrailsRails Version4.0.0 Updatebeta
RubyonrailsRails Version4.0.0 Updaterc1
RubyonrailsRails Version4.0.0 Updaterc2
RubyonrailsRails Version4.0.1 Update-
RubyonrailsRails Version4.0.1 Updaterc1
RubyonrailsRails Version4.0.1 Updaterc2
RubyonrailsRails Version4.0.1 Updaterc3
RubyonrailsRails Version4.0.1 Updaterc4
RubyonrailsRails Version4.0.2
RubyonrailsRails Version4.0.3
RubyonrailsRails Version4.0.4
RubyonrailsRails Version4.0.5
RubyonrailsRails Version4.0.6
RubyonrailsRails Version4.0.6 Updaterc1
RubyonrailsRails Version4.0.6 Updaterc2
RubyonrailsRails Version4.0.6 Updaterc3
RubyonrailsRails Version4.0.7
RubyonrailsRails Version4.0.8
RubyonrailsRails Version4.1.0 Update-
RubyonrailsRails Version4.1.0 Updatebeta1
RubyonrailsRails Version4.1.1
RubyonrailsRails Version4.1.2
RubyonrailsRails Version4.1.2 Updaterc1
RubyonrailsRails Version4.1.2 Updaterc2
RubyonrailsRails Version4.1.2 Updaterc3
RubyonrailsRails Version4.1.3
RubyonrailsRails Version4.1.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.53
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P