---
title: "CVE-2014-3514\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-3514?format=md
keywords: index, follow
---

# CVE-2014-3514

Publication date 20 August 2014

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

activerecord/lib/active\_record/relation/query\_methods.rb in Active Record
in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote
attackers to bypass the strong parameters protection mechanism via crafted
input to an application that makes create\_with calls.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2014-3514?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| rails | 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Ignored end of life |
| rails-3.2 | 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |
| rails-4.0 | 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |
| ruby-actionpack-2.3 | 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Not in release |
| ruby-actionpack-3.2 | 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |
| ruby-activerecord-2.3 | 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Not in release |
| ruby-activerecord-3.2 | 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |
| ruby-activesupport-2.3 | 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Not in release |
| ruby-activesupport-3.2 | 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |
| ruby-rails-2.3 | 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |
| 10.04 LTS lucid | Not in release |
| ruby-rails-3.2 | 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [seth-arnold](https://launchpad.net/~seth-arnold)

in Oneiric-Saucy, rails package is just for transition

---

### [jdstrand](https://launchpad.net/~jdstrand)

per Debian, only affects 4.0.0 and all later Versions

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3514)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-3514)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-3514)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-3514)

### Other references

* <https://groups.google.com/forum/message/raw?msg=rubyonrails-security/M4chq5Sb540/CC1Fh0Y_NWwJ>
* <http://openwall.com/lists/oss-security/2014/08/18/10>
* <https://www.cve.org/CVERecord?id=CVE-2014-3514>
