CVE-2015-7577
published 2016-02-16CVE-2015-7577: activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x…
PriorityP335medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
4.25%
89.9th percentile
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| activerecord_project | activerecord | >= 3.1.0 < 3.2.22.1 | 3.2.22.1 |
| activerecord_project | activerecord | >= 4.0.0 < 4.1.14.1 | 4.1.14.1 |
| activerecord_project | activerecord | >= 4.2.0 < 4.2.5.1 | 4.2.5.1 |
| activerecord_project | activerecord | >= 5.0.0.beta1 < 5.0.0.beta1.1 | 5.0.0.beta1.1 |
| debian | rails | < rails 2:4.2.5.1-1 (bookworm) | rails 2:4.2.5.1-1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-activerecord: Nested attributes rejection proc bypass in Active Record
vendor_redhat·2016-01-25·CVSS 5.3
CVE-2015-7577 [MEDIUM] rubygem-activerecord: Nested attributes rejection proc bypass in Active Record
rubygem-activerecord: Nested attributes rejection proc bypass in Active Record
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.
A flaw was found in the Active Record component's handling of nested attributes in combination with the destroy flag. An attacker could possibly use this flaw to set attributes to invalid values or clear all attributes.
Package: ruby193-rubygem-activerecord (CloudForms Management Engine 5.2) - Affected
Package: ruby193-rubygem-activereco
Debian
CVE-2015-7577: rails - activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on ...
vendor_debian·2015·CVSS 5.3
CVE-2015-7577 [MEDIUM] CVE-2015-7577: rails - activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on ...
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.
Scope: local
bookworm: resolved (fixed in 2:4.2.5.1-1)
bullseye: resolved (fixed in 2:4.2.5.1-1)
forky: resolved (fixed in 2:4.2.5.1-1)
sid: resolved (fixed in 2:4.2.5.1-1)
trixie: resolved (fixed in 2:4.2.5.1-1)
OSV
Active Record Improper Access Control
osv·2017-10-24
CVE-2015-7577 [MEDIUM] Active Record Improper Access Control
Active Record Improper Access Control
`activerecord/lib/active_record/nested_attributes.rb` in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.
GHSA
Active Record Improper Access Control
ghsa·2017-10-24
CVE-2015-7577 [MEDIUM] CWE-284 Active Record Improper Access Control
Active Record Improper Access Control
`activerecord/lib/active_record/nested_attributes.rb` in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.
OSV
CVE-2015-7577: activerecord/lib/active_record/nested_attributes
osv·2016-02-16·CVSS 5.3
CVE-2015-7577 [MEDIUM] CVE-2015-7577: activerecord/lib/active_record/nested_attributes
activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.
No detection rules found.
No public exploits indexed.
HackerOne
Nested attributes reject_if proc can be circumvented by providing "_destroy" parameter
hackerone·2016-02-12·CVSS 5.3
CVE-2015-7577 [MEDIUM] Nested attributes reject_if proc can be circumvented by providing "_destroy" parameter
Nested attributes reject_if proc can be circumvented by providing "_destroy" parameter
Nested attributes rejection proc bypass in Active Record.
There is a vulnerability in how the nested attributes feature in Active Record
handles updates in combination with destroy flags when destroying records is
disabled. This vulnerability has been assigned the CVE identifier CVE-2015-7577.
Versions Affected: 3.1.0 and newer
Not affected: 3.0.x and older
Fixed Versions: 5.0.0.beta1.1, 4.2.5.1, 4.1.14.1, 3.2.22.1
Impact
When using the nested attributes feature in Active Record you can prevent the
destruction of associated records by passing the `allow_destroy: false` option
to the `accepts_nested_attributes_for` method. However due to a change in the
commit [a9b4b5d][1] the `_destroy` flag prevents
Bugzilla
CVE-2015-7577 rubygem-activerecord: rubygem-activerecord: Nested attributes rejection proc bypass in Active Record [fedora-all]
bugzilla·2016-01-26·CVSS 5.3
CVE-2015-7577 [MEDIUM] CVE-2015-7577 rubygem-activerecord: rubygem-activerecord: Nested attributes rejection proc bypass in Active Record [fedora-all]
CVE-2015-7577 rubygem-activerecord: rubygem-activerecord: Nested attributes rejection proc bypass in Active Record [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2015-7577 rubygem-activerecord: Nested attributes rejection proc bypass in Active Record
bugzilla·2016-01-26·CVSS 5.3
CVE-2015-7577 [MEDIUM] CVE-2015-7577 rubygem-activerecord: Nested attributes rejection proc bypass in Active Record
CVE-2015-7577 rubygem-activerecord: Nested attributes rejection proc bypass in Active Record
There was reported a vulnerability in how the nested attributes feature in Active Record handles updates in combination with destroy flags when destroying records is disabled. When using the nested attributes feature in Active Record you can prevent the destruction of associated records by passing the `allow_destroy: false` option to the `accepts_nested_attributes_for` method. However due to a change in the commit [a9b4b5d][1] the `_destroy` flag prevents the `:reject_if` proc from being called because it assumes that the record will be destroyed anyway. However if `:allow_destroy` is false this leads to changes that would have been rejected being applied to the record. Attackers could use this do
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178041.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178065.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00043.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0296.htmlhttp://www.debian.org/security/2016/dsa-3464http://www.openwall.com/lists/oss-security/2016/01/25/10http://www.securityfocus.com/bid/81806http://www.securitytracker.com/id/1034816https://groups.google.com/forum/message/raw?msg=ruby-security-ann/cawsWcQ6c8g/LATIsglZEgAJhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178041.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178065.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00043.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0296.htmlhttp://www.debian.org/security/2016/dsa-3464http://www.openwall.com/lists/oss-security/2016/01/25/10http://www.securityfocus.com/bid/81806http://www.securitytracker.com/id/1034816https://groups.google.com/forum/message/raw?msg=ruby-security-ann/cawsWcQ6c8g/LATIsglZEgAJ
2016-02-16
Published