CVE-2013-0276
published 2013-02-13CVE-2013-0276: ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection…
PriorityP427medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.46%
82.6th percentile
ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activerecord_project | activerecord | >= 0 < 2.3.17 | 2.3.17 |
| activerecord_project | activerecord | >= 3.1.0 < 3.1.11 | 3.1.11 |
| activerecord_project | activerecord | >= 3.2.0 < 3.2.12 | 3.2.12 |
| debian | rails | < rails 2.3.14.1 (bookworm) | rails 2.3.14.1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected
vendor_redhat·2013-02-11·CVSS 4.3
CVE-2013-0276 [MEDIUM] rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected
rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected
ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.
Debian
CVE-2013-0276: rails - ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x befo...
vendor_debian·2013·CVSS 4.3
CVE-2013-0276 [MEDIUM] CVE-2013-0276: rails - ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x befo...
ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: resolved (fixed in 2.3.14.1)
sid: resolved (fixed in 2.3.14.1)
trixie: resolved (fixed in 2.3.14.1)
OSV
ActiveRecord vulnerable to modification of protected model attributes
osv·2017-10-24
CVE-2013-0276 [MEDIUM] ActiveRecord vulnerable to modification of protected model attributes
ActiveRecord vulnerable to modification of protected model attributes
ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the `attr_protected` protection mechanism and modify protected model attributes via a crafted request.
GHSA
ActiveRecord vulnerable to modification of protected model attributes
ghsa·2017-10-24
CVE-2013-0276 [MEDIUM] CWE-284 ActiveRecord vulnerable to modification of protected model attributes
ActiveRecord vulnerable to modification of protected model attributes
ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the `attr_protected` protection mechanism and modify protected model attributes via a crafted request.
OSV
CVE-2013-0276: ActiveRecord in Ruby on Rails before 2
osv·2013-02-13·CVSS 4.3
CVE-2013-0276 [MEDIUM] CVE-2013-0276: ActiveRecord in Ruby on Rails before 2
ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0276 rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected [fedora-all]
bugzilla·2013-04-05·CVSS 4.3
CVE-2013-0276 [MEDIUM] CVE-2013-0276 rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected [fedora-all]
CVE-2013-0276 rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Plea
Bugzilla
CVE-2013-0276 rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected [epel-5]
bugzilla·2013-04-05·CVSS 4.3
CVE-2013-0276 [MEDIUM] CVE-2013-0276 rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected [epel-5]
CVE-2013-0276 rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epe
Bugzilla
CVE-2013-0276 rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected
bugzilla·2013-02-09·CVSS 4.3
CVE-2013-0276 [MEDIUM] CVE-2013-0276 rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected
CVE-2013-0276 rubygem-activerecord/rubygem-activemodel: circumvention of attr_protected
Aaron Patterson ([email protected]) reports:
Circumvention of attr_protected
There is a vulnerability in the attr_protected method in ActiveRecord. This
vulnerability has been assigned the CVE identifier CVE-2013-0276.
Versions Affected: All.
Not affected: Applications using attr_accessible
Fixed Versions: 3.2.12, 3.1.11
Impact
The attr_protected method allows developers to specify a blacklist of model
attributes which users should not be allowed to assign to. By using a
specially crafted request, attackers could circumvent this protection and
alter values that were meant to be protected.
All users running an affected release should either upgrade or use one of the
work arounds immediately.
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-03/msg00048.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0686.htmlhttp://secunia.com/advisories/52112http://secunia.com/advisories/52774http://support.apple.com/kb/HT5784http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/http://www.debian.org/security/2013/dsa-2620http://www.openwall.com/lists/oss-security/2013/02/11/5http://www.osvdb.org/90072http://www.securityfocus.com/bid/57896https://groups.google.com/group/rubyonrails-security/msg/bb44b98a73ef1a06?dmode=source&output=gplainhttp://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-03/msg00048.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0686.htmlhttp://secunia.com/advisories/52112http://secunia.com/advisories/52774http://support.apple.com/kb/HT5784http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/http://www.debian.org/security/2013/dsa-2620http://www.openwall.com/lists/oss-security/2013/02/11/5http://www.osvdb.org/90072http://www.securityfocus.com/bid/57896https://groups.google.com/group/rubyonrails-security/msg/bb44b98a73ef1a06?dmode=source&output=gplain
2013-02-13
Published