CVE-2014-3514
Publication date 20 August 2014
Last updated 24 July 2024
Ubuntu priority
activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.
Status
Package | Ubuntu Release | Status |
---|---|---|
rails | 14.04 LTS trusty | Not in release |
rails-3.2 | 14.04 LTS trusty | Not in release |
rails-4.0 | 14.04 LTS trusty | Not in release |
ruby-actionpack-2.3 | 14.04 LTS trusty | Not in release |
ruby-actionpack-3.2 | 14.04 LTS trusty | Not in release |
ruby-activerecord-2.3 | 14.04 LTS trusty | Not in release |
ruby-activerecord-3.2 | 14.04 LTS trusty | Not in release |
ruby-activesupport-2.3 | 14.04 LTS trusty | Not in release |
ruby-activesupport-3.2 | 14.04 LTS trusty | Not in release |
ruby-rails-2.3 | 14.04 LTS trusty | Not in release |
ruby-rails-3.2 | 14.04 LTS trusty | Not in release |
Notes
seth-arnold
in Oneiric-Saucy, rails package is just for transition
jdstrand
per Debian, only affects 4.0.0 and all later Versions