CVE-2014-3514: High severity ruby on rails vulnerability
activerecord/lib/activerecord/relation/querymethods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes createwith calls.
Other sources
activerecord/lib/activerecord/relation/querymethods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes createwith calls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3514?
CVE-2014-3514 is classified as a moderate severity vulnerability.
How do I fix CVE-2014-3514?
To fix CVE-2014-3514, upgrade Active Record to version 4.0.9 or 4.1.5 or later.
What software is affected by CVE-2014-3514?
CVE-2014-3514 affects Ruby on Rails versions 4.0.x before 4.0.9 and 4.1.x before 4.1.5.
Can CVE-2014-3514 be exploited remotely?
Yes, CVE-2014-3514 allows remote attackers to bypass strong parameters protection.
What are the consequences of CVE-2014-3514 exploitation?
If exploited, CVE-2014-3514 could lead to unauthorized access to application data.