CVE-2016-0753Improper Input Validation in Rails

Severity
5.3MEDIUMNVD
EPSS
2.3%
top 15.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 16
Latest updateOct 24

Description

Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDrubyonrails/rails4.1.04.1.14.1+2
Debianrubyonrails/rails< 2:4.2.5.1-1+3
NVDopensuse/leap42.1

Also affects: Debian Linux 8.0, Fedora 22, 23

🔴Vulnerability Details

4
OSV
activemodel contains Improper Input Validation2017-10-24
GHSA
activemodel contains Improper Input Validation2017-10-24
CVEList
CVE-2016-0753: Active Model in Ruby on Rails 42016-02-16
OSV
CVE-2016-0753: Active Model in Ruby on Rails 42016-02-16

📋Vendor Advisories

2
Red Hat
rubygem-activerecord: possible input validation circumvention in Active Model2016-01-25
Debian
CVE-2016-0753: rails - Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5...2016

💬Community

4
HackerOne
Validation bypass for Active Record and Active Model2016-02-12
Bugzilla
CVE-2016-0753 rubygem-activerecord: rubygem-activemodel: Possible Input Validation Circumvention in Active Model [fedora-all]2016-01-26
Bugzilla
CVE-2016-0753 rubygem-activemodel: Possible Input Validation Circumvention in Active Model [fedora-all]2016-01-26
Bugzilla
CVE-2016-0753 rubygem-activerecord: possible input validation circumvention in Active Model2016-01-26
CVE-2016-0753 — Improper Input Validation in Rails | cvebase