Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-A3498CEEF02311DE6410ECF58BAB69DF
HistoryAug 20, 2014 - 12:00 a.m.

Strong Parameter bypass with create_with

2014-08-2000:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
8

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.007 Low

EPSS

Percentile

80.9%

The create_with functionality in Active Record was implemented incorrectly and completely bypasses the strong parameter protection.

Affected configurations

Vulners
Node
gemactiverecordRange4.0.0>
OR
gemactiverecordRange<4.0.9
OR
gemactiverecordRange4.1.0>
OR
gemactiverecordRange<4.1.5

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.007 Low

EPSS

Percentile

80.9%