CVE-2013-0276
Publication date 13 February 2013
Last updated 24 July 2024
Ubuntu priority
ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.
Status
Package | Ubuntu Release | Status |
---|---|---|
rails | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
ruby-activerecord-2.3 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
ruby-activerecord-3.2 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
Notes
Patch details
Package | Patch details |
---|---|
rails |
|
ruby-activerecord-2.3 | |
ruby-activerecord-3.2 |