CVE-2014-3514

EUVD-2017-0209
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
Affected Products (NVD)
VendorProductVersion
rubyonrailsrails
4.0.0
rubyonrailsrails
4.0.0:beta
rubyonrailsrails
4.0.0:rc1
rubyonrailsrails
4.0.0:rc2
rubyonrailsrails
4.0.1
rubyonrailsrails
4.0.1:rc1
rubyonrailsrails
4.0.1:rc2
rubyonrailsrails
4.0.1:rc3
rubyonrailsrails
4.0.1:rc4
rubyonrailsrails
4.0.2
rubyonrailsrails
4.0.3
rubyonrailsrails
4.0.4
rubyonrailsrails
4.0.5
rubyonrailsrails
4.0.6
rubyonrailsrails
4.0.6:rc1
rubyonrailsrails
4.0.6:rc2
rubyonrailsrails
4.0.6:rc3
rubyonrailsrails
4.0.7
rubyonrailsrails
4.0.8
rubyonrailsrails
4.1.0
rubyonrailsrails
4.1.0:beta1
rubyonrailsrails
4.1.1
rubyonrailsrails
4.1.2
rubyonrailsrails
4.1.2:rc1
rubyonrailsrails
4.1.2:rc2
rubyonrailsrails
4.1.2:rc3
rubyonrailsrails
4.1.3
rubyonrailsrails
4.1.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rails
bookworm
2:6.1.7.3+dfsg-2~deb12u1
fixed
bullseye
2:6.0.3.7+dfsg-2+deb11u2
fixed
bullseye (security)
2:6.0.3.7+dfsg-2+deb11u2
fixed
sid
2:6.1.7.3+dfsg-4
fixed
trixie
2:6.1.7.3+dfsg-4
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rails
lucid
ignored
precise
not-affected
trusty
dne
rails-3.2
lucid
dne
precise
dne
trusty
dne
rails-4.0
lucid
dne
precise
dne
trusty
dne
ruby-actionpack-2.3
lucid
dne
precise
not-affected
trusty
dne
ruby-actionpack-3.2
lucid
dne
precise
dne
trusty
dne
ruby-activerecord-2.3
lucid
dne
precise
not-affected
trusty
dne
ruby-activerecord-3.2
lucid
dne
precise
dne
trusty
dne
ruby-activesupport-2.3
lucid
dne
precise
not-affected
trusty
dne
ruby-activesupport-3.2
lucid
dne
precise
dne
trusty
dne
ruby-rails-2.3
lucid
dne
precise
not-affected
trusty
dne
ruby-rails-3.2
lucid
dne
precise
dne
trusty
dne
Common Weakness Enumeration