Lucene search

K
cvelistRedhatCVELIST:CVE-2015-7577
HistoryFeb 16, 2016 - 2:00 a.m.

CVE-2015-7577

2016-02-1602:00:00
redhat
www.cve.org
1

5.5 Medium

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.0%

activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.

5.5 Medium

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.0%