Ruby on Rails 'ActiveRecord' Module Security Bypass Vulnerability
BID:65648
Info
Ruby on Rails 'ActiveRecord' Module Security Bypass Vulnerability
| Bugtraq ID: | 65648 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0080 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2014 12:00AM |
| Updated: | Apr 13 2015 09:49PM |
| Credit: | Godfrey Chan,Godfrey Chan |
| Vulnerable: |
Ruby on Rails Ruby on Rails 4.1 beta1 Ruby on Rails Ruby on Rails 4.0.2 Ruby on Rails Ruby on Rails 4.0.1 Ruby on Rails Ruby on Rails 4.0 |
| Not Vulnerable: |
Ruby on Rails Ruby on Rails 4.1 beta2 Ruby on Rails Ruby on Rails 4.0.3 |
Discussion
Ruby on Rails 'ActiveRecord' Module Security Bypass Vulnerability
Ruby on Rails is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Ruby on Rails 4.0.0, 4.0.1, 4.0.2 and 4.1.0.beta1 are vulnerable.
Ruby on Rails is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Ruby on Rails 4.0.0, 4.0.1, 4.0.2 and 4.1.0.beta1 are vulnerable.
Exploit / POC
Ruby on Rails 'ActiveRecord' Module Security Bypass Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
References
Ruby on Rails 'ActiveRecord' Module Security Bypass Vulnerability
References:
References:
- Release Notes - 3.2.17, 4.0.3 and 4.1.0 beta2 (Ruby on Rails)
- Ruby on Rails Homepage (Ruby on Rails)