CVE-2016-0753 — Improper Input Validation in Rails
Severity
5.3MEDIUMNVD
EPSS
2.3%
top 15.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 16
Latest updateOct 24
Description
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages3 packages
Also affects: Debian Linux 8.0, Fedora 22, 23
🔴Vulnerability Details
4📋Vendor Advisories
2💬Community
4Bugzilla▶
CVE-2016-0753 rubygem-activerecord: rubygem-activemodel: Possible Input Validation Circumvention in Active Model [fedora-all]↗2016-01-26
Bugzilla▶
CVE-2016-0753 rubygem-activemodel: Possible Input Validation Circumvention in Active Model [fedora-all]↗2016-01-26
Bugzilla▶
CVE-2016-0753 rubygem-activerecord: possible input validation circumvention in Active Model↗2016-01-26