CVE-2014-3514
published 2014-08-20CVE-2014-3514: activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.80%
85.0th percentile
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activerecord_project | activerecord | >= 4.0.0 < 4.0.9 | 4.0.9 |
| activerecord_project | activerecord | >= 4.1.0 < 4.1.5 | 4.1.5 |
| debian | rails | < rails 2:4.1.5-1 (bookworm) | rails 2:4.1.5-1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | >= 0 < 2:4.1.5-1 | 2:4.1.5-1 |
| rubyonrails | rails | >= 0 < 2:4.1.5-1 | 2:4.1.5-1 |
| rubyonrails | rails | >= 0 < 2:4.1.5-1 | 2:4.1.5-1 |
| rubyonrails | rails | >= 0 < 2:4.1.5-1 | 2:4.1.5-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Active Record subject to strong parameters protection bypass
ghsa·2017-10-24
CVE-2014-3514 [HIGH] CWE-284 Active Record subject to strong parameters protection bypass
Active Record subject to strong parameters protection bypass
`activerecord/lib/active_record/relation/query_methods.rb` in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes `create_with` calls.
OSV
Active Record subject to strong parameters protection bypass
osv·2017-10-24
CVE-2014-3514 [HIGH] Active Record subject to strong parameters protection bypass
Active Record subject to strong parameters protection bypass
`activerecord/lib/active_record/relation/query_methods.rb` in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes `create_with` calls.
OSV
CVE-2014-3514: activerecord/lib/active_record/relation/query_methods
osv·2014-08-20·CVSS 7.5
CVE-2014-3514 [HIGH] CVE-2014-3514: activerecord/lib/active_record/relation/query_methods
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
Red Hat
rubygem-activerecord: Strong Parameter bypass with create_with
vendor_redhat·2014-08-18·CVSS 7.5
CVE-2014-3514 [HIGH] CWE-88 rubygem-activerecord: Strong Parameter bypass with create_with
rubygem-activerecord: Strong Parameter bypass with create_with
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
It was discovered that Active Record's create_with method failed to properly check attributes passed to it. A remote attacker could possibly use this flaw to bypass the strong parameter protection and modify arbitrary model attributes via mass assignment if an application using Active Record called create_with with untrusted values.
Package: cfme-gemset (CloudForms Management Engine 5) - Not affected
Package: ruby193-rubygem-activerecord (CloudForms Man
Debian
CVE-2014-3514: rails - activerecord/lib/active_record/relation/query_methods.rb in Active Record in Rub...
vendor_debian·2014·CVSS 7.5
CVE-2014-3514 [HIGH] CVE-2014-3514: rails - activerecord/lib/active_record/relation/query_methods.rb in Active Record in Rub...
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
Scope: local
bookworm: resolved (fixed in 2:4.1.5-1)
bullseye: resolved (fixed in 2:4.1.5-1)
forky: resolved (fixed in 2:4.1.5-1)
sid: resolved (fixed in 2:4.1.5-1)
trixie: resolved (fixed in 2:4.1.5-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3514 rubygem-activerecord: Strong Parameter bypass with create_with [fedora-20]
bugzilla·2014-08-25·CVSS 7.5
CVE-2014-3514 [HIGH] CVE-2014-3514 rubygem-activerecord: Strong Parameter bypass with create_with [fedora-20]
CVE-2014-3514 rubygem-activerecord: Strong Parameter bypass with create_with [fedora-20]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
fedora-20 tracking bug for rubygem-activereco
Bugzilla
CVE-2014-3514 rubygem-activerecord: Strong Parameter bypass with create_with
bugzilla·2014-08-18·CVSS 7.5
CVE-2014-3514 [HIGH] CVE-2014-3514 rubygem-activerecord: Strong Parameter bypass with create_with
CVE-2014-3514 rubygem-activerecord: Strong Parameter bypass with create_with
Rafael Mendonça França reports:
There is a vulnerability in the create_with method in Active Record. This
vulnerability has been assigned the CVE identifier CVE-2014-3514.
Versions Affected: 4.0.0 and All Later Versions.
Not affected: Versions earlier than 4.0.0
Fixed Versions: 4.0.9 4.1.5
Impact
The create_with functionality in Active Record was implemented incorrectly
and completely bypasses the strong parameters protection. Applications
which pass user-controlled values to create_with could allow attackers to
set arbitrary attributes on models.
All users running an affected release should either upgrade or use one of
the workarounds immediately.
Releases
The 4.0.9 and 4.1.5 releases are available at the n
http://openwall.com/lists/oss-security/2014/08/18/10http://rhn.redhat.com/errata/RHSA-2014-1102.htmlhttp://secunia.com/advisories/60347https://groups.google.com/forum/message/raw?msg=rubyonrails-security/M4chq5Sb540/CC1Fh0Y_NWwJhttp://openwall.com/lists/oss-security/2014/08/18/10http://rhn.redhat.com/errata/RHSA-2014-1102.htmlhttp://secunia.com/advisories/60347https://groups.google.com/forum/message/raw?msg=rubyonrails-security/M4chq5Sb540/CC1Fh0Y_NWwJ
2014-08-20
Published