Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11296
HistoryJan 15, 2019 - 8:59 a.m.

SQL Injection In Query_methods

2019-01-1508:59:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.007 Low

EPSS

Percentile

80.9%

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.