CVE-2016-0753
published 2016-02-16CVE-2016-0753: Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class…
PriorityP339medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
7.16%
93.6th percentile
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | rails | < rails 2:4.2.5.1-1 (bookworm) | rails 2:4.2.5.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | >= 0 < 2:4.2.5.1-1 | 2:4.2.5.1-1 |
| rubyonrails | rails | >= 0 < 2:4.2.5.1-1 | 2:4.2.5.1-1 |
| rubyonrails | rails | >= 0 < 2:4.2.5.1-1 | 2:4.2.5.1-1 |
| rubyonrails | rails | >= 0 < 2:4.2.5.1-1 | 2:4.2.5.1-1 |
| rubyonrails | rails | >= 4.1.0 < 4.1.14.1 | 4.1.14.1 |
| rubyonrails | rails | >= 4.2.0 < 4.2.5.1 | 4.2.5.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-activerecord: possible input validation circumvention in Active Model
vendor_redhat·2016-01-25·CVSS 5.3
CVE-2016-0753 [MEDIUM] CWE-20 rubygem-activerecord: possible input validation circumvention in Active Model
rubygem-activerecord: possible input validation circumvention in Active Model
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
A flaw was found in the way the Active Model based models processed attributes. An attacker with the ability to pass arbitrary attributes to models could possibly use this flaw to bypass input validation.
Mitigation: Do not allow arbitrary attributes to be passed to models. In Rails with Strong Parameters, make sure to not call permit! method, which bypasses strong parameters protections. Outside of rails, use whitelisting to filter only allowed attributes
Debian
CVE-2016-0753: rails - Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5...
vendor_debian·2016·CVSS 5.3
CVE-2016-0753 [MEDIUM] CVE-2016-0753: rails - Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5...
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
Scope: local
bookworm: resolved (fixed in 2:4.2.5.1-1)
bullseye: resolved (fixed in 2:4.2.5.1-1)
forky: resolved (fixed in 2:4.2.5.1-1)
sid: resolved (fixed in 2:4.2.5.1-1)
trixie: resolved (fixed in 2:4.2.5.1-1)
OSV
activemodel contains Improper Input Validation
osv·2017-10-24
CVE-2016-0753 [MEDIUM] activemodel contains Improper Input Validation
activemodel contains Improper Input Validation
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
GHSA
activemodel contains Improper Input Validation
ghsa·2017-10-24
CVE-2016-0753 [MEDIUM] CWE-20 activemodel contains Improper Input Validation
activemodel contains Improper Input Validation
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
OSV
CVE-2016-0753: Active Model in Ruby on Rails 4
osv·2016-02-16·CVSS 5.3
CVE-2016-0753 [MEDIUM] CVE-2016-0753: Active Model in Ruby on Rails 4
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
No detection rules found.
No public exploits indexed.
HackerOne
Validation bypass for Active Record and Active Model
hackerone·2016-02-12·CVSS 5.3
CVE-2016-0753 [MEDIUM] Validation bypass for Active Record and Active Model
Validation bypass for Active Record and Active Model
Possible Input Validation Circumvention in Active Model
There is a possible input validation circumvention vulnerability in Active
Model. This vulnerability has been assigned the CVE identifier CVE-2016-0753.
Versions Affected: 4.1.0 and newer
Not affected: 4.0.13 and older
Fixed Versions: 5.0.0.beta1.1, 4.2.5.1, 4.1.14.1
Impact
Code that uses Active Model based models (including Active Record models) and
does not validate user input before passing it to the model can be subject to
an attack where specially crafted input will cause the model to skip
validations.
Vulnerable code will look something like this:
```ruby
SomeModel.new(unverified_user_input)
```
Rails users using Strong Parameters are generally not impacted by this issu
Bugzilla
CVE-2016-0753 rubygem-activerecord: rubygem-activemodel: Possible Input Validation Circumvention in Active Model [fedora-all]
bugzilla·2016-01-26·CVSS 5.3
CVE-2016-0753 [MEDIUM] CVE-2016-0753 rubygem-activerecord: rubygem-activemodel: Possible Input Validation Circumvention in Active Model [fedora-all]
CVE-2016-0753 rubygem-activerecord: rubygem-activemodel: Possible Input Validation Circumvention in Active Model [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: th
Bugzilla
CVE-2016-0753 rubygem-activemodel: Possible Input Validation Circumvention in Active Model [fedora-all]
bugzilla·2016-01-26·CVSS 5.3
CVE-2016-0753 [MEDIUM] CVE-2016-0753 rubygem-activemodel: Possible Input Validation Circumvention in Active Model [fedora-all]
CVE-2016-0753 rubygem-activemodel: Possible Input Validation Circumvention in Active Model [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2016-0753 rubygem-activerecord: possible input validation circumvention in Active Model
bugzilla·2016-01-26·CVSS 5.3
CVE-2016-0753 [MEDIUM] CVE-2016-0753 rubygem-activerecord: possible input validation circumvention in Active Model
CVE-2016-0753 rubygem-activerecord: possible input validation circumvention in Active Model
A possible input validation circumvention vulnerability in Active Model was reported. Code that uses Active Model based models (including Active Record models) and does not validate user input before passing it to the model can be subject to an attack where specially crafted input will cause the model to skip validations.
External References:
https://groups.google.com/forum/#!msg/rubyonrails-security/6jQVC1geukQ/8oYETcxbFQAJ
http://weblog.rubyonrails.org/2016/1/25/Rails-5-0-0-beta1-1-4-2-5-1-4-1-14-1-3-2-22-1-and-rails-html-sanitizer-1-0-3-have-been-released/
Discussion:
Created rubygem-activerecord tracking bugs for this issue:
Affects: fedora-all [bug 1301979]
---
Created rubygem-activemod
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178041.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178043.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178047.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178065.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00043.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0296.htmlhttp://www.debian.org/security/2016/dsa-3464http://www.openwall.com/lists/oss-security/2016/01/25/14http://www.securityfocus.com/bid/82247http://www.securitytracker.com/id/1034816https://groups.google.com/forum/message/raw?msg=ruby-security-ann/6jQVC1geukQ/3Iy0GU1ZEgAJhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178041.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178043.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178047.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178065.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00043.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0296.htmlhttp://www.debian.org/security/2016/dsa-3464http://www.openwall.com/lists/oss-security/2016/01/25/14http://www.securityfocus.com/bid/82247http://www.securitytracker.com/id/1034816https://groups.google.com/forum/message/raw?msg=ruby-security-ann/6jQVC1geukQ/3Iy0GU1ZEgAJ
2016-02-16
Published