Improper authorization control for web services In activerecord
Description
ActiveRecord vulnerable to modification of protected model attributes
ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rubygems | 2.3.17, 3.1.11, 3.2.12 | ||
debian 12 | 2.3.14.1 | ||
debian 13 | 2.3.14.1 | ||
debian 14 | 2.3.14.1 | ||
rubygems | 3.1.11, 3.2.12 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11.