GHSA-hm48-76wh-q86v

Suggest an improvement
Source
https://github.com/advisories/GHSA-hm48-76wh-q86v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-hm48-76wh-q86v/GHSA-hm48-76wh-q86v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hm48-76wh-q86v
Withdrawn
2020-06-17T15:14:48Z
Published
2018-08-21T19:03:17Z
Modified
2024-12-02T05:42:37Z
Summary
High severity vulnerability that affects activerecord
Details

Withdrawn, accidental duplicate publish.

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

Database specific
{
    "cwe_ids": [],
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-17T15:14:48Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

RubyGems / activerecord

Package

Name
activerecord
Purl
pkg:gem/activerecord

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.0.9

Affected versions

4.*
4.0.0
4.0.1.rc1
4.0.1.rc2
4.0.1.rc3
4.0.1.rc4
4.0.1
4.0.2
4.0.3
4.0.4.rc1
4.0.4
4.0.5
4.0.6.rc1
4.0.6.rc2
4.0.6.rc3
4.0.6
4.0.7
4.0.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-hm48-76wh-q86v/GHSA-hm48-76wh-q86v.json"

RubyGems / activerecord

Package

Name
activerecord
Purl
pkg:gem/activerecord

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.1.0
Fixed
4.1.5

Affected versions

4.*
4.1.0
4.1.1
4.1.2.rc1
4.1.2.rc2
4.1.2.rc3
4.1.2
4.1.3
4.1.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-hm48-76wh-q86v/GHSA-hm48-76wh-q86v.json"